Sanderson Forensics Forums - Powered by vBulletin
  • Register
  • Help

  • Home page
    • Sanderson Forensics
  • Software
  • Purchase Software
  • Re-licence software
  • Blog/Articles
  • Support Forum
  • User Blogs
  • Advanced Search
  • Home
  • Home
  • Software
  • Forensic Browser extensions

  1. This site uses cookies. By continuing to browse the site, you are agreeing to our use of cookies.
  • Forensic Browser extensions

    ESE/EDB/JetBlue Database extension for the Forensic Browser 

    by
    Paul
    • View Profile
    • View Forum Posts
    • Private Message
    • View Blog Entries
    • View Articles
     Number of Views: 8907 
    Article Preview

    Forensic Browser for SQLite – ESE extension

    ESE, Extensible Storage Engine or Jet Blue databases as I am sure most are aware are a proprietary database format used extensively by Microsoft both on Windows phones and Windows computers. They are used in many applications including Exchange, Internet Explorer, Active Directory and Cortana. While there are a few different applications that allow you to view the content of the database there is nothing to my knowledge that allows you to perform queries and joins on the different tables using SQL, ...
    Read More Read More

    Skype media cache 

    by
    Paul
    • View Profile
    • View Forum Posts
    • Private Message
    • View Blog Entries
    • View Articles
    Published on 19th May 2015 15:37  Number of Views: 9960 

    This extension is based on an article I wrote a few weeks ago, so I won't go over it now but rather point you to the extensive information within that article: ...
    Read More Read More

    Tango blob decoder 

    by
    Paul
    • View Profile
    • View Forum Posts
    • Private Message
    • View Blog Entries
    • View Articles
    Published on 19th May 2015 14:48  Number of Views: 8191 
    Article Preview

    The Tango messenging application stores its message data in the payload column as blobs within the messages table, further these blobs are base 64 encoded. User data is also encoded in the profilescache.db database.
    ...
    Read More Read More

    Facebook orca2.db blob decoder 

    by
    Paul
    • View Profile
    • View Forum Posts
    • Private Message
    • View Blog Entries
    • View Articles
    Published on 17th May 2015 16:10  Number of Views: 12262 
    Article Preview

    The FaceBook orca extension has now been replaced by a built in feature of the Forensic Browser - more information here.

    Under IOS Facebook store the content of messages in compound structure within ...
    Read More Read More

    Kik binary plist decoder 

    by
    Paul
    • View Profile
    • View Forum Posts
    • Private Message
    • View Blog Entries
    • View Articles
    Published on 16th May 2015 16:29  Number of Views: 9304 
    Article Preview

    Kik on IOS devices stores attachments/pictures which are sent with messages in binary PLists external to the SQLite database. Clearly when creating a report it would be useful to display any pictures alongside the message to which they belong. This extension ...
    Read More Read More

    Skype ChatSync extension 

    by
    Paul
    • View Profile
    • View Forum Posts
    • Private Message
    • View Blog Entries
    • View Articles
    Published on 26th February 2015 16:40  Number of Views: 6487 
    Article Preview

    This Forensic Browser extension parses all of the files in the Skype ChatSync folder extracting usernames and associated Lan and Wan IP adresses. With an appropriate third party ipinfodb account IP addresses can ...
    Read More Read More

  • Follow @sandersonforens
  • Navigation

    • Software
      • Purchase software UK £
      • Purchase software USD
      • Purchase software Euro
      • Re-license software UK £
      • Re-licence software USD
      • Re-licence software Euro
      • Free software
      • Forensic Browser extensions
    • Blog/Articles
    • Contact
    • About us
  • Recent Articles


    Investigating a database using foreign keys

    Read More



    How NOT to examine SQLite WAL files

    Read More



    Why can't I see who sent that deleted IOS SMS message

    Read More



    SMS recovered records and contacts - three ways

    Read More



    Forensic Browser for SQLite - Structured Storage Manager

    Read More



    Using the Forensic Browser for SQLite to display maps based on data from exiftool

    Read More



    Q. When is secure delete not secure?

    Read More


    WAL timelining Correlated subquery

    Read More



    Determining when a record was deleted in SQLite

    Read More



    Identifying deleted records in DB and WAL

    Read More


  • Contact Us
  • Sanderson Forensics
  • Top
All times are GMT. The time now is 19:12.
Powered by vBulletin® Version 4.2.5 Release Candidate 1
Copyright © 2018 vBulletin Solutions Inc. All rights reserved.
Sanderson Forensics