SLAMorris Final Thesis After Corrections.pdf - Cranfield University
SLAMorris Final Thesis After Corrections.pdf - Cranfield University
SLAMorris Final Thesis After Corrections.pdf - Cranfield University
You also want an ePaper? Increase the reach of your titles
YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.
6 The structure and behaviour of the Windows 7 Operating System<br />
Thumbnail Cache ........................................................................................... 105<br />
6.1 Introduction ........................................................................................... 105<br />
6.2 Methodology ......................................................................................... 106<br />
6.3 Default installation................................................................................. 108<br />
6.3.1 Initial Searches ............................................................................... 108<br />
6.3.2 Initial state of the thumbnail cache ................................................. 109<br />
6.4 Identifying the structure ......................................................................... 109<br />
6.4.1 Methodology ................................................................................... 110<br />
6.4.2 The thumbnail cache directory structure ........................................ 113<br />
6.4.3 thumbcache_idx ............................................................................. 114<br />
6.4.4 thumbcache_32, 96, 256 and 1024 ................................................ 116<br />
6.4.5 thumbcache_sr ............................................................................... 121<br />
6.5 Identifying the behaviour ....................................................................... 122<br />
6.5.1 The creation of records and subrecords ......................................... 122<br />
6.5.2 The modification of records and subrecords .................................. 130<br />
6.5.3 The deletion of records and subrecords ......................................... 133<br />
6.5.4 Fragmentation of the thumbnail cache ........................................... 134<br />
6.6 Identifying traces left outside the thumbnail cache ............................... 134<br />
6.6.1 Windows.edb .................................................................................. 136<br />
6.6.2 Registry .......................................................................................... 136<br />
6.6.3 Shortcuts ........................................................................................ 138<br />
6.6.4 External Media ............................................................................... 139<br />
6.6.5 Encrypted Containers ..................................................................... 140<br />
6.7 Alteration of thumbnail cache artefacts ................................................. 141<br />
6.7.1 Metadata ........................................................................................ 141<br />
6.7.2 Visual thumbnail ............................................................................. 142<br />
6.7.3 Original source file ......................................................................... 143<br />
6.8 Forming a relationship between the thumbnail subrecords and the<br />
source files .................................................................................................. 143<br />
6.8.1 Visual Thumbnail ............................................................................ 144<br />
6.8.2 Metadata ........................................................................................ 145<br />
6.8.3 Thumbnail cache ID ....................................................................... 146<br />
6.8.4 Event timeline ................................................................................. 147<br />
6.9 Audio and Media thumbnails ................................................................. 148<br />
6.9.1 Audio thumbnails ............................................................................ 148<br />
6.9.2 Media thumbnails ........................................................................... 150<br />
6.10 Discussion .......................................................................................... 151<br />
6.10.1 Provenance of Artefacts ............................................................... 152<br />
6.10.2 Interpretation of Results ............................................................... 154<br />
6.11 Conclusion .......................................................................................... 155<br />
7 Identification of thumbnail cache fragments ................................................ 157<br />
vii