logo

Thumbnail forensics. DFIR techniques for analysing Windows Thumbcache

ID: 5d6ff521-64cb-5240-8545-86176027d864

STIX ID: report--5d6ff521-64cb-5240-8545-86176027d864

Feed Name: Pen Test Partners Blog

Date Published: 2025-08-08

Date Updated: 2026-03-26

Author: Joe Bursell

...
...

This report explains how Windows thumbnail cache (thumbcache) can be leveraged in forensic investigations to reveal deleted or hidden content and reconstruct user activity, including interpreting thumbnail sizes (e.g., 1280 vs. 96) to infer viewing behavior, locating and parsing cache files, and correlating with Shellbags, Prefetch, USN Journal, and event logs. A short insider-threat case study illustrates building a timeline that links folder access, file viewing, and deletions, showing how thumbcache combined with other artifacts can provide strong, corroborated evidence.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.