Supported Formats¶
The information below is based of version 1.5.0
File formats¶
Apple System Log (ASL)
Android usage-history (app usage)
Bencode files
Chrome preferences
CUPS IPP
Extensible Storage Engine (ESE) Database File (EDB) format using libesedb
Firefox Cache
Jump Lists .customDestinations-ms files
MacOS Application firewall
MacOS Securityd
MacOS Wifi
McAfee Anti-Virus Logs
Microsoft Internet Explorer History File Format (also known as MSIE 4 - 9 Cache Files or index.dat) using libmsiecf
Microsoft IIS log files
NTFS $MFT and $UsnJrnl:$J using libfsntfs
OLE Compound File using libolecf
OpenXML
Pcap files
Portable Executable (PE) files using pefile
PL SQL cache file (PL-SQL developer recall files)
Popularity Contest log
Property list (plist) format using plistlib
SCCM client logs
SELinux audit logs
SkyDrive log and error log files
SQLite database format using SQLite
Symantec AV Corporate Edition and Endpoint Protection log
Syslog
Windows Firewall
Windows Job files (also known as “at jobs”)
Windows Recycle bin (INFO2 and $I/$R)
Windows Shortcut File (LNK) format using liblnk (including shell item support)
Xchat and Xchat scrollback files
Zsh history files
Bencode file formats¶
Transmission
uTorrent
ESE database file formats¶
Internet Explorer WebCache format
Windows 8 File History
OLE Compound File formats¶
Document summary information
Summary information (top-level only)
Jump Lists .automaticDestinations-ms files
Property list (plist) formats¶
Airport
Apple Account
Bluetooth
Install History
iPod/iPhone
Mac User
Software Update
Spotlight
Spotlight Volume Information
Timemachine
SQLite database file formats¶
Android call logs
Android SMS
Chrome cookies
Chrome browsing and downloads history
Chrome Extension activity
Firefox cookies
Firefox browsing and downloads history
Google Drive
iMessage (iOS and MacOS)
Kik (iOS)
Launch services quarantine events
MacKeeper cache
MacOS document versions
Skype text conversations
Twitter (iOS)
Zeitgeist activity database
Windows Registry formats¶
AppCompatCache
BagMRU (or ShellBags)
CCleaner
Less Frequently Used (LFU)
MountPoints2
Most Recently Used (MRU) MRUList and MRUListEx (including shell item support)
MSIE Zones
Office MRU
Outlook Search
Run and RunOnce keys
SAM
Services
Shutdown
Task Scheduler Cache (Task Cache)
Terminal Server MRU
Timezones
Typed URLS
USB
USBStor
UserAssist
WinRar
Windows version information
Hashers Supported¶
MD5
SHA1
SHA256