No Time to Waste
ID: b897df66-94df-55e0-997f-a4e2e246110f
STIX ID: report--b897df66-94df-55e0-997f-a4e2e246110f
Feed Name: Group-IB Blog
This report examines the Windows 10 Timeline artifact (ActivitiesCache.db), describing where it resides, its SQLite schema and key tables (Activity, Activity_PackageId), and how its timestamps and residual data can aid investigations for up to 30 days. It outlines practical workflows and tools—DB Browser for SQLite, WxTCmd, Magnet AXIOM, and Belkasoft—to parse and analyze activity records, including cloud sync metadata. The paper demonstrates how Timeline can reveal attacker behavior (e.g., TeamViewer installation/log access and Mimikatz execution) to support incident response and event reconstruction.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
