Skip to content

Series

Investigating with the Windows Search index

5 posts in this series. Read them in order or jump to any one.

  1. How to Open Windows.edb and Windows.db (Step by Step)

    Step-by-step: open and analyse a Windows Search index (Windows.edb or Windows.db) in your browser, read the flags, filter, and export a CSV for your timeline.

  2. Windows Search Index: Evidence of Deleted Files

    How the Windows Search index keeps paths, metadata and text of deleted files, where each trace survives in Windows.edb and Windows.db, and how to verify it.

  3. Windows Search Index Investigation: A Worked Example

    A fictional intrusion on FIN-WKS-07 worked end to end from the Windows Search index: staging, a deleted credentials file, USB exfiltration and cloud upload.

  4. Windows Search Index Anti-Forensics and Its Limits

    How the Windows Search index gets disabled, rebuilt, compacted or deleted, what each action leaves behind, and how to argue from a missing or empty index.

  5. Windows.edb Parser Comparison: SIDR, ESEDatabaseView & More

    A fair comparison of Windows Search index parsers: SIDR, WinSearchDBAnalyzer, ESEDatabaseView, libesedb's esedbexport, sqlite3 and this browser-based parser.

All posts in this series