Understanding index. DAT files the meaning of the two 64-bit windows timestamps in the various index

Source: Internet
Author: User

The "index. dat "file is a database file used to manage, among other things, MSIE browser functions. there is an "index. dat "in the cookie folder, one in the" History "folder, one in each daily history folder, one in each weekly history folder, and one sitting at the root of the content. ie5 folder under Temporary Internet Files (Cache folder ).

The Times stored in the various index dot DAT files have different meanings depending on where they are found. at URL record offsets 9 and 17 are two 64-bit windows time stamps. there meanings are described in the below table:

Location of index. dat

1st date located

Record offset 9

2nd date located

Record offset 17

Comments

Cookie folder

Cookie modified GMT

Cookie file last accessed GMT

 

Main history

Last visited time GMT

Last visited time GMT

 

Daily history

Last visited time (local time !)

Last visited time GMT

 

Weekly history

Last visited time (local time !)

File Created time (GMT)

This means the File Creation Time of the containing index dot DAT file!

Cache

Last modified by web server time (GMT)

Last checked by local host time GMT

 

Some scripts/tools apply the local offset to all dates as most are stored in GMT. note that if the local time offset is applied to the first date for daily and weekly history, this timestamp will be incorrect as the offset will have been applied twice, once by MSIE and once again by your tool or script.

If you are going to be testifying about a timestamp, understand thoroughly its meaning, based on its location, and verify that your tool is reporting the timestamp correctly by going to the raw data. it is better yet recreate some data on a test box so that you can work through it, understanding both MSIE and your tools.

For information about identifying URL fragments as to their source file, see:

Http://www.stevebunting.org/udpd4n6/forensics/index_dat1.htm

For an example of the meanings of the dates in weekly history index. dat, including the location of the raw data for these timestamps, see the following encase mini-report.

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.