Repository logo
 
Publication

A Digital Forensic View of Windows 10 Notifications

dc.contributor.authorDomingues, Patricio
dc.contributor.authorAndrade, Luís
dc.contributor.authorFrade, Miguel
dc.date.accessioned2022-02-02T10:09:04Z
dc.date.available2022-02-02T10:09:04Z
dc.date.issued2022-01-31
dc.description.abstractWindows Push Notifications (WPN) is a relevant part of Windows 10 interaction with the user. It is comprised of badges, tiles and toasts. Important and meaningful data can be conveyed by notifications, namely by so-called toasts that can popup with information regarding a new incoming email or a recent message from a social network. In this paper, we analyze the Windows 10 Notification systems from a digital forensic perspective, focusing on the main forensic artifacts conveyed by WPN. We also briefly analyze Windows 11 first release’s WPN system, observing that internal data structures are practically identical to Windows 10. We provide an open source Python 3 command line application to parse and extract data from the Windows Push Notification SQLite3 database, and a Jython module that allows the well-known Autopsy digital forensic software to interact with the application and thus to also parse and process Windows Push Notifications forensic artifacts. From our study, we observe that forensic data provided by WPN are scarce, although they still need to be considered, namely if traditional Windows forensic artifacts are not available. Furthermore, toasts are clearly WPN’s most relevant source of forensic data.pt_PT
dc.description.versioninfo:eu-repo/semantics/publishedVersionpt_PT
dc.identifier.citationDomingues, P.; Andrade, L.; Frade, M. A Digital Forensic View of Windows 10 Notifications. Forensic. Sci. 2022, 2, 88–106. https://doi.org/ 10.3390/forensicsci2010007pt_PT
dc.identifier.doihttps://doi.org/ 10.3390/forensicsci2010007pt_PT
dc.identifier.urihttp://hdl.handle.net/10400.8/6587
dc.language.isoengpt_PT
dc.peerreviewedyespt_PT
dc.publisherMDPIpt_PT
dc.relationUIDB/CEC/ -4524/2020pt_PT
dc.relationUIDB/EEA/50008/2020pt_PT
dc.relation.ispartofseries1;
dc.relation.publisherversionhttps://www.mdpi.com/2673-6756/2/1/7/htmpt_PT
dc.rights.urihttp://creativecommons.org/licenses/by/4.0/pt_PT
dc.subjectDigital forensicspt_PT
dc.subjectWindows 10pt_PT
dc.subjectWindows 11pt_PT
dc.subjectPush notificationspt_PT
dc.subjectSqlite3pt_PT
dc.titleA Digital Forensic View of Windows 10 Notificationspt_PT
dc.typejournal article
dspace.entity.typePublication
oaire.citation.endPage106pt_PT
oaire.citation.startPage88pt_PT
oaire.citation.titleForensic Sciencespt_PT
oaire.citation.volume2pt_PT
person.familyNameDomingues
person.familyNameFrade
person.givenNamePatrício
person.givenNameMiguel
person.identifier1234758
person.identifier.ciencia-idAA15-6185-C477
person.identifier.ciencia-idA512-9B28-1CEC
person.identifier.orcid0000-0002-6207-6292
person.identifier.orcid0000-0002-4405-7696
person.identifier.scopus-author-id13411315400
person.identifier.scopus-author-id24468034000
rcaap.rightsopenAccesspt_PT
rcaap.typearticlept_PT
relation.isAuthorOfPublicationb88ada5f-0d8b-4e55-ab0a-62aa82ea1388
relation.isAuthorOfPublication95a3fa7a-d37e-45e9-9acb-44c083582fea
relation.isAuthorOfPublication.latestForDiscovery95a3fa7a-d37e-45e9-9acb-44c083582fea

Files