Abstract
The Extensible Storage Engine (ESE) database is a data storage technology developed by Microsoft. It is mainly used by Windows OS and its web browser. It is possible to easily delete a table or a record in the database using the ESENT API. However, there are insufficient papers and relevant information how about recovering deleted records. Previous works apply only to some tables and fail to recover deleted data perfectly. In this paper, we analyzed the structure of the ESE database and present a general-use technique to recover deleted records and tables. We developed a tool to implement the technique, and assessed the performance of the proposed tool.
Original language | English |
---|---|
Pages | S118-S124 |
DOIs | |
Publication status | Published - 2016 Aug 7 |
Event | 16th Annual USA Digital Forensics Research Conference, DFRWS 2016 USA - Seattle, United States Duration: 2016 Aug 7 → 2016 Aug 10 |
Conference
Conference | 16th Annual USA Digital Forensics Research Conference, DFRWS 2016 USA |
---|---|
Country/Territory | United States |
City | Seattle |
Period | 16/8/7 → 16/8/10 |
Keywords
- ESE database analysis
- ESE database forensic
- Windows forensic
ASJC Scopus subject areas
- Information Systems