SQLiteDatabases
Author: Andrew Rathbun
description
SQLDatabases Target for use with SQLECmd Module
paths
C:\Users\%user%\AppData\Local\4kdownload.com\4K Video Downloader\4K Video Downloader*.sqliteGrabs database(s) that stores user download history
C:\Users\%user%\AppData\Local\Packages\Microsoft.Office.OneNote_8wekyb3d8bbwe\LocalState\AppData\Local\OneNote\*\FullTextSearchIndexGrabs database(s) comprising of each OneNote notebook's text content
C:\Users\%user%\AppData\Local\Packages\Microsoft.Office.OneNote_8wekyb3d8bbwe\LocalState\AppData\Local\OneNote\NotificationsRecentNotebooks_SeenURLsGrabs a file that appears to record recently seen OneNote notebooks
C:\Users\%user%\AppData\Local\Packages\Microsoft.Office.OneNote_8wekyb3d8bbwe\LocalState\AppData\Local\OneNote\16.0\AccessibilityCheckerIndexGrabs database(s) comprising of each OneNote notebook's version sync error history
C:\Users\%user%\AppData\Local\Packages\Microsoft.Office.OneNote_8wekyb3d8bbwe\LocalState\AppData\Local\OneNote\16.0\NoteTags*LiveId.dbGrabs a database that stores the user specified tags within OneNote to be used application-wide
C:\Users\%user%\AppData\Local\Packages\Microsoft.Office.OneNote_8wekyb3d8bbwe\LocalState\AppData\Local\OneNote\16.0\RecentSearchesRecentSearches.dbGrabs a database that stores the user's recent searches within OneNote
C:\Users\%user%\AppData\Local\Packages\Microsoft.MicrosoftStickyNotes*\LocalState\plum.sqlite*C:\Users\%user%\AppData\Local\Packages\Microsoft.Todos_8wekyb3d8bbwe\LocalState\AccountsRoot\*\todosqlite.db*C:\Program Files\Robo-FTP *\ProgramData\SchedulerService.sqliteC:\Users\%user%\AppData\Roaming\TeraCopy\History*.dbC:\Users\%user%\AppData\Roaming\TeraCopy\main.dbC:\Users\%user%\AppData\Roaming\Notionnotion.dbC:\ProgramData\IDrive\IBCOMMON\*\LDBNEW\*\*.idbsC:\Users\%user%\AppData\Local\Dropbox\*\filecache.db*Getting individual files because folder may contain very large extraneous files
C:\Users\%user%\AppData\Local\Dropbox\*\config.dbxGetting individual files because folder may contain very large extraneous files
C:\Users\%user%\AppData\Local\Dropbox\*\home.dbSQlite database which appears to keep track of the user's recent Dropbox activity
C:\Users\%user%\AppData\Local\Dropbox\*\icon.dbSQLite database which appears to keep track of icons in the user's Drobox sync history which can give an indication as to which files and folders are present
C:\Users\%user%\AppData\Local\Dropbox\*\sync_history.dbSQLite database which appears to keep track of the user's Drobox sync history
C:\Users\%user%\AppData\Local\Dropbox\*\sync\nucleus.sqlite3*SQLite database which appears to contain a table for deleted files
C:\Users\%user%\AppData\Local\Dropbox\host.dbSQLite database which contains the local path of the user's Dropbox folder encoded in BASE64. Decode each line separately, not together.
C:\Users\%user%\AppData\Local\Dropbox\host.dbxSQLite database which contains the local path of the user's Dropbox folder encoded in BASE64. Decode each line separately, not together.
C:\Users\%user%\AppData\Local\Dropbox\*\sync\aggregation.dbxSQLite database which appears to contain snapshot table of the user's Dropbox contents in JSON with timestamps in UNIX Epoch
C:\Users\%user%\AppData\Local\Dropbox\*\avatarcache.dbSQLite database which appears to contain the ID's of account(s) on the user's system where Dropbox is installed
C:\Users\%user%\AppData\Local\Dropbox\*\avatarcache.dbSQLite database which appears to contain the ID's of account(s) on the user's system where Dropbox is installed
C:\Users\%user%\AppData\Local\Google\Drive\*\cloud_graph\cloud_graph.dbWindows_GoogleDrive_CloudGraphDB.smap
C:\Users\%user%\AppData\Local\Google\Drive\*\TempData\*\change_buffer\DB(s) with seemingly randomized filename(s) that track file system changes within Google Drive
C:\Users\%user%\AppData\Local\Google\Drive\*\snapshot.dbWindows_GoogleDrive_SnapshotDB.smap
C:\Users\%user%\AppData\Local\Google\Drive\*\sync_config.dbWindows_GoogleDrive_SyncConfigDB.smap
C:\Users\%user%\AppData\Roaming\FileZilla\*.sqlite3*C:\Documents and Settings\%user%\Local Settings\Application Data\Google\Chrome\User Data\*\Bookmarks*C:\Documents and Settings\%user%\Local Settings\Application Data\Google\Chrome\User Data\*\Cookies*C:\Documents and Settings\%user%\Local Settings\Application Data\Google\Chrome\User Data\*\Current SessionC:\Documents and Settings\%user%\Local Settings\Application Data\Google\Chrome\User Data\*\Current TabsC:\Documents and Settings\%user%\Local Settings\Application Data\Google\Chrome\User Data\*\Favicons*C:\Documents and Settings\%user%\Local Settings\Application Data\Google\Chrome\User Data\*\History*C:\Documents and Settings\%user%\Local Settings\Application Data\Google\Chrome\User Data\*\Last SessionC:\Documents and Settings\%user%\Local Settings\Application Data\Google\Chrome\User Data\*\Last TabsC:\Documents and Settings\%user%\Local Settings\Application Data\Google\Chrome\User Data\*\Login DataC:\Documents and Settings\%user%\Local Settings\Application Data\Google\Chrome\User Data\*\PreferencesC:\Documents and Settings\%user%\Local Settings\Application Data\Google\Chrome\User Data\*\Shortcuts*C:\Documents and Settings\%user%\Local Settings\Application Data\Google\Chrome\User Data\*\Top Sites*C:\Documents and Settings\%user%\Local Settings\Application Data\Google\Chrome\User Data\*\Visited LinksC:\Documents and Settings\%user%\Local Settings\Application Data\Google\Chrome\User Data\*\Web Data*C:\Users\%user%\AppData\Local\Google\Chrome\User Data\*\Bookmarks*C:\Users\%user%\AppData\Local\Google\Chrome\User Data\*\Cookies*C:\Users\%user%\AppData\Local\Google\Chrome\User Data\*\Current SessionC:\Users\%user%\AppData\Local\Google\Chrome\User Data\*\Current TabsC:\Users\%user%\AppData\Local\Google\Chrome\User Data\*\Download MetadataC:\Users\%user%\AppData\Local\Google\Chrome\User Data\*\Extension CookiesC:\Users\%user%\AppData\Local\Google\Chrome\User Data\*\Favicons*C:\Users\%user%\AppData\Local\Google\Chrome\User Data\*\History*C:\Users\%user%\AppData\Local\Google\Chrome\User Data\*\Last SessionC:\Users\%user%\AppData\Local\Google\Chrome\User Data\*\Last TabsC:\Users\%user%\AppData\Local\Google\Chrome\User Data\*\Login DataC:\Users\%user%\AppData\Local\Google\Chrome\User Data\*\Media History*C:\Users\%user%\AppData\Local\Google\Chrome\User Data\*\Network Action PredictorC:\Users\%user%\AppData\Local\Google\Chrome\User Data\*\Network Persistent StateC:\Users\%user%\AppData\Local\Google\Chrome\User Data\*\PreferencesC:\Users\%user%\AppData\Local\Google\Chrome\User Data\*\QuotaManagerC:\Users\%user%\AppData\Local\Google\Chrome\User Data\*\Reporting and NELC:\Users\%user%\AppData\Local\Google\Chrome\User Data\*\Shortcuts*C:\Users\%user%\AppData\Local\Google\Chrome\User Data\*\Top Sites*C:\Users\%user%\AppData\Local\Google\Chrome\User Data\*\Trust Tokens*C:\Users\%user%\AppData\Local\Google\Chrome\User Data\*\Sync DataSyncData.sqlite3C:\Users\%user%\AppData\Local\Google\Chrome\User Data\*\Visited LinksC:\Users\%user%\AppData\Local\Google\Chrome\User Data\*\Web Data*C:\Users\%user%\AppData\Local\Microsoft\Edge\User Data\*\Bookmarks*C:\Users\%user%\AppData\Local\Microsoft\Edge\User Data\*\CollectionscollectionsSQLiteC:\Users\%user%\AppData\Local\Microsoft\Edge\User Data\*\Cookies*C:\Users\%user%\AppData\Local\Microsoft\Edge\User Data\*\Current SessionC:\Users\%user%\AppData\Local\Microsoft\Edge\User Data\*\Current TabsC:\Users\%user%\AppData\Local\Microsoft\Edge\User Data\*\Favicons*C:\Users\%user%\AppData\Local\Microsoft\Edge\User Data\*\History*C:\Users\%user%\AppData\Local\Microsoft\Edge\User Data\*\Last SessionC:\Users\%user%\AppData\Local\Microsoft\Edge\User Data\*\Last TabsC:\Users\%user%\AppData\Local\Microsoft\Edge\User Data\*\Login DataC:\Users\%user%\AppData\Local\Microsoft\Edge\User Data\*\Media History*C:\Users\%user%\AppData\Local\Microsoft\Edge\User Data\*\Network Action PredictorC:\Users\%user%\AppData\Local\Microsoft\Edge\User Data\*\PreferencesC:\Users\%user%\AppData\Local\Microsoft\Edge\User Data\*\Shortcuts*C:\Users\%user%\AppData\Local\Microsoft\Edge\User Data\*\Top Sites*C:\Users\%user%\AppData\Local\Microsoft\Edge\User Data\*\Sync DataSyncData.sqlite3C:\Users\%user%\AppData\Local\Microsoft\Edge\User Data\*\Bookmarks*C:\Users\%user%\AppData\Local\Microsoft\Edge\User Data\*\Visited LinksC:\Users\%user%\AppData\Local\Microsoft\Edge\User Data\*\Web Data*C:\Users\%user%\AppData\Roaming\Mozilla\Firefox\Profiles\*\addons.sqlite*C:\Users\%user%\AppData\Roaming\Mozilla\Firefox\Profiles\*\weave\bookmarks.sqlite*C:\Users\%user%\AppData\Roaming\Mozilla\Firefox\Profiles\*\cookies.sqlite*C:\Users\%user%\AppData\Roaming\Mozilla\Firefox\Profiles\*\firefox_cookies.sqlite*C:\Users\%user%\AppData\Roaming\Mozilla\Firefox\Profiles\*\downloads.sqlite*C:\Users\%user%\AppData\Roaming\Mozilla\Firefox\Profiles\*\favicons.sqlite*C:\Users\%user%\AppData\Roaming\Mozilla\Firefox\Profiles\*\formhistory.sqlite*C:\Users\%user%\AppData\Roaming\Mozilla\Firefox\Profiles\*\permissions.sqlite*C:\Users\%user%\AppData\Roaming\Mozilla\Firefox\Profiles\*\places.sqlite*C:\Users\%user%\AppData\Roaming\Mozilla\Firefox\Profiles\*\protections.sqlite*C:\Users\%user%\AppData\Roaming\Mozilla\Firefox\Profiles\*\search.sqlite*C:\Users\%user%\AppData\Roaming\Mozilla\Firefox\Profiles\*\signons.sqlite*C:\Users\%user%\AppData\Roaming\Mozilla\Firefox\Profiles\*\storage-sync.sqlite*C:\Users\%user%\AppData\Roaming\Mozilla\Firefox\Profiles\*\webappstore.sqlite*C:\Users\%user%\AppData\Local\Microsoft\Windows\Notifications\wpndatabase.dbC:\Users\%user%\AppData\Local\Microsoft\Windows\Notifications\appdb.datC:\Users\%user%\AppData\Local\ConnectedDevicesPlatform\*\ActivitiesCache.db*C:\ProgramData\USOPrivate\UpdateStorestore.dbC:\Program Files*\Bitdefender*\regex:*.+\.(db|db-wal|db-shm)Bitdefender SQLite databases
C:\ProgramData\Microsoft\Diagnosis\EventTranscriptEventTranscript.db*C:\Windows.old\ProgramData\Microsoft\Diagnosis\EventTranscriptEventTranscript.db*collection commands
# PowerShell Artifact Collection Script
# Target: SQLiteDatabases
# Run as Administrator
#Requires -RunAsAdministrator
$ErrorActionPreference = "SilentlyContinue"
$DestBase = "D:\Evidence"
# Function to handle directory creation and copying
function Collect-Artifact {
param (
[string]$SourcePath,
[string]$FolderName
)
$FullDest = Join-Path -Path $DestBase -ChildPath $FolderName
if (-not (Test-Path -Path $FullDest)) {
New-Item -ItemType Directory -Path $FullDest -Force | Out-Null
}
Copy-Item -Path $SourcePath -Destination $FullDest -Recurse -Force
}
# 1. 4K Video Downloader
$UserPath = Join-Path $env:USERPROFILE "AppData\Local\4kdownload.com\4K Video Downloader\4K Video Downloader"
Collect-Artifact -SourcePath "$UserPath\*.sqlite" -FolderName "4K_Video_Downloader"
# 2. Microsoft OneNote - FullTextSearchIndex
$UserPath = Join-Path $env:USERPROFILE "AppData\Local\Packages\Microsoft.Office.OneNote_8wekyb3d8bbwe\LocalState\AppData\Local\OneNote\*\FullTextSearchIndex"
Collect-Artifact -SourcePath "$UserPath\*" -FolderName "Microsoft_OneNote___FullTextSearchIndex"
# 3. Microsoft OneNote - RecentNotebooks_SeenURLs
$UserPath = Join-Path $env:USERPROFILE "AppData\Local\Packages\Microsoft.Office.OneNote_8wekyb3d8bbwe\LocalState\AppData\Local\OneNote\Notifications"
Collect-Artifact -SourcePath "$UserPath\RecentNotebooks_SeenURLs" -FolderName "Microsoft_OneNote___RecentNotebooks_SeenURLs"
# 4. Microsoft OneNote - AccessibilityCheckerIndex
$UserPath = Join-Path $env:USERPROFILE "AppData\Local\Packages\Microsoft.Office.OneNote_8wekyb3d8bbwe\LocalState\AppData\Local\OneNote\16.0\AccessibilityCheckerIndex"
Collect-Artifact -SourcePath "$UserPath\*" -FolderName "Microsoft_OneNote___AccessibilityCheckerIndex"
# 5. Microsoft OneNote - User NoteTags
$UserPath = Join-Path $env:USERPROFILE "AppData\Local\Packages\Microsoft.Office.OneNote_8wekyb3d8bbwe\LocalState\AppData\Local\OneNote\16.0\NoteTags"
Collect-Artifact -SourcePath "$UserPath\*LiveId.db" -FolderName "Microsoft_OneNote___User_NoteTags"
# 6. Microsoft OneNote - RecentSearches
$UserPath = Join-Path $env:USERPROFILE "AppData\Local\Packages\Microsoft.Office.OneNote_8wekyb3d8bbwe\LocalState\AppData\Local\OneNote\16.0\RecentSearches"
Collect-Artifact -SourcePath "$UserPath\RecentSearches.db" -FolderName "Microsoft_OneNote___RecentSearches"
# 7. Microsoft Sticky Notes - 1607 and later
$UserPath = Join-Path $env:USERPROFILE "AppData\Local\Packages\Microsoft.MicrosoftStickyNotes*\LocalState\"
Collect-Artifact -SourcePath "$UserPath\plum.sqlite*" -FolderName "Microsoft_Sticky_Notes___1607_and_later"
# 8. Microsoft To Do - SQLite Database of To Do tasks
$UserPath = Join-Path $env:USERPROFILE "AppData\Local\Packages\Microsoft.Todos_8wekyb3d8bbwe\LocalState\AccountsRoot\*\"
Collect-Artifact -SourcePath "$UserPath\todosqlite.db*" -FolderName "Microsoft_To_Do___SQLite_Database_of_To_Do_tasks"
# 9. Robo-FTP Jobs
Collect-Artifact -SourcePath "C:\Program Files\Robo-FTP *\ProgramData\\SchedulerService.sqlite" -FolderName "Robo_FTP_Jobs"
# 10. TeraCopy - History Databases
$UserPath = Join-Path $env:USERPROFILE "AppData\Roaming\TeraCopy\History"
Collect-Artifact -SourcePath "$UserPath\*.db" -FolderName "TeraCopy___History_Databases"
# 11. TeraCopy - Main Database
$UserPath = Join-Path $env:USERPROFILE "AppData\Roaming\TeraCopy\"
Collect-Artifact -SourcePath "$UserPath\main.db" -FolderName "TeraCopy___Main_Database"
# 12. Notion Local Storage
$UserPath = Join-Path $env:USERPROFILE "AppData\Roaming\Notion"
Collect-Artifact -SourcePath "$UserPath\notion.db" -FolderName "Notion_Local_Storage"
# 13. IDrive Backed Up Files
Collect-Artifact -SourcePath "C:\ProgramData\IDrive\IBCOMMON\*\LDBNEW\*\\*.idbs" -FolderName "IDrive_Backed_Up_Files"
# 14. Dropbox Metadata
$UserPath = Join-Path $env:USERPROFILE "AppData\Local\Dropbox\*\"
Collect-Artifact -SourcePath "$UserPath\filecache.db*" -FolderName "Dropbox_Metadata"
# 15. Dropbox Metadata
$UserPath = Join-Path $env:USERPROFILE "AppData\Local\Dropbox\*\"
Collect-Artifact -SourcePath "$UserPath\config.dbx" -FolderName "Dropbox_Metadata"
# 16. Dropbox Metadata
$UserPath = Join-Path $env:USERPROFILE "AppData\Local\Dropbox\*\"
Collect-Artifact -SourcePath "$UserPath\home.db" -FolderName "Dropbox_Metadata"
# 17. Dropbox Metadata
$UserPath = Join-Path $env:USERPROFILE "AppData\Local\Dropbox\*\"
Collect-Artifact -SourcePath "$UserPath\icon.db" -FolderName "Dropbox_Metadata"
# 18. Dropbox Metadata
$UserPath = Join-Path $env:USERPROFILE "AppData\Local\Dropbox\*\"
Collect-Artifact -SourcePath "$UserPath\sync_history.db" -FolderName "Dropbox_Metadata"
# 19. Dropbox Metadata
$UserPath = Join-Path $env:USERPROFILE "AppData\Local\Dropbox\*\sync\"
Collect-Artifact -SourcePath "$UserPath\nucleus.sqlite3*" -FolderName "Dropbox_Metadata"
# 20. Dropbox Metadata
$UserPath = Join-Path $env:USERPROFILE "AppData\Local\Dropbox\"
Collect-Artifact -SourcePath "$UserPath\host.db" -FolderName "Dropbox_Metadata"
# 21. Dropbox Metadata
$UserPath = Join-Path $env:USERPROFILE "AppData\Local\Dropbox\"
Collect-Artifact -SourcePath "$UserPath\host.dbx" -FolderName "Dropbox_Metadata"
# 22. Dropbox Metadata
$UserPath = Join-Path $env:USERPROFILE "AppData\Local\Dropbox\*\sync\"
Collect-Artifact -SourcePath "$UserPath\aggregation.dbx" -FolderName "Dropbox_Metadata"
# 23. Dropbox Metadata
$UserPath = Join-Path $env:USERPROFILE "AppData\Local\Dropbox\*\"
Collect-Artifact -SourcePath "$UserPath\avatarcache.db" -FolderName "Dropbox_Metadata"
# 24. Dropbox Metadata
$UserPath = Join-Path $env:USERPROFILE "AppData\Local\Dropbox\*\"
Collect-Artifact -SourcePath "$UserPath\avatarcache.db" -FolderName "Dropbox_Metadata"
# 25. Google File Stream Metadata
$UserPath = Join-Path $env:USERPROFILE "AppData\Local\Google\Drive\*\cloud_graph\"
Collect-Artifact -SourcePath "$UserPath\cloud_graph.db" -FolderName "Google_File_Stream_Metadata"
# 26. Google File Stream Metadata
$UserPath = Join-Path $env:USERPROFILE "AppData\Local\Google\Drive\*\TempData\*\change_buffer\"
Collect-Artifact -SourcePath "$UserPath\*" -FolderName "Google_File_Stream_Metadata"
# 27. Google File Stream Metadata
$UserPath = Join-Path $env:USERPROFILE "AppData\Local\Google\Drive\*\"
Collect-Artifact -SourcePath "$UserPath\snapshot.db" -FolderName "Google_File_Stream_Metadata"
# 28. Google File Stream Metadata
$UserPath = Join-Path $env:USERPROFILE "AppData\Local\Google\Drive\*\"
Collect-Artifact -SourcePath "$UserPath\sync_config.db" -FolderName "Google_File_Stream_Metadata"
# 29. FileZilla SQLite3 Log Files
$UserPath = Join-Path $env:USERPROFILE "AppData\Roaming\FileZilla\"
Collect-Artifact -SourcePath "$UserPath\*.sqlite3*" -FolderName "FileZilla_SQLite3_Log_Files"
# 30. Chrome bookmarks XP
$UserPath = Join-Path $env:USERPROFILE "Local Settings\Application Data\Google\Chrome\User Data\*\"
Collect-Artifact -SourcePath "$UserPath\Bookmarks*" -FolderName "Chrome_bookmarks_XP"
# 31. Chrome Cookies XP
$UserPath = Join-Path $env:USERPROFILE "Local Settings\Application Data\Google\Chrome\User Data\*\"
Collect-Artifact -SourcePath "$UserPath\Cookies*" -FolderName "Chrome_Cookies_XP"
# 32. Chrome Current Session XP
$UserPath = Join-Path $env:USERPROFILE "Local Settings\Application Data\Google\Chrome\User Data\*\"
Collect-Artifact -SourcePath "$UserPath\Current Session" -FolderName "Chrome_Current_Session_XP"
# 33. Chrome Current Tabs XP
$UserPath = Join-Path $env:USERPROFILE "Local Settings\Application Data\Google\Chrome\User Data\*\"
Collect-Artifact -SourcePath "$UserPath\Current Tabs" -FolderName "Chrome_Current_Tabs_XP"
# 34. Chrome Favicons XP
$UserPath = Join-Path $env:USERPROFILE "Local Settings\Application Data\Google\Chrome\User Data\*\"
Collect-Artifact -SourcePath "$UserPath\Favicons*" -FolderName "Chrome_Favicons_XP"
# 35. Chrome History XP
$UserPath = Join-Path $env:USERPROFILE "Local Settings\Application Data\Google\Chrome\User Data\*\"
Collect-Artifact -SourcePath "$UserPath\History*" -FolderName "Chrome_History_XP"
# 36. Chrome Last Session XP
$UserPath = Join-Path $env:USERPROFILE "Local Settings\Application Data\Google\Chrome\User Data\*\"
Collect-Artifact -SourcePath "$UserPath\Last Session" -FolderName "Chrome_Last_Session_XP"
# 37. Chrome Last Tabs XP
$UserPath = Join-Path $env:USERPROFILE "Local Settings\Application Data\Google\Chrome\User Data\*\"
Collect-Artifact -SourcePath "$UserPath\Last Tabs" -FolderName "Chrome_Last_Tabs_XP"
# 38. Chrome Login Data XP
$UserPath = Join-Path $env:USERPROFILE "Local Settings\Application Data\Google\Chrome\User Data\*\"
Collect-Artifact -SourcePath "$UserPath\Login Data" -FolderName "Chrome_Login_Data_XP"
# 39. Chrome Preferences XP
$UserPath = Join-Path $env:USERPROFILE "Local Settings\Application Data\Google\Chrome\User Data\*\"
Collect-Artifact -SourcePath "$UserPath\Preferences" -FolderName "Chrome_Preferences_XP"
# 40. Chrome Shortcuts XP
$UserPath = Join-Path $env:USERPROFILE "Local Settings\Application Data\Google\Chrome\User Data\*\"
Collect-Artifact -SourcePath "$UserPath\Shortcuts*" -FolderName "Chrome_Shortcuts_XP"
# 41. Chrome Top Sites XP
$UserPath = Join-Path $env:USERPROFILE "Local Settings\Application Data\Google\Chrome\User Data\*\"
Collect-Artifact -SourcePath "$UserPath\Top Sites*" -FolderName "Chrome_Top_Sites_XP"
# 42. Chrome Visited Links XP
$UserPath = Join-Path $env:USERPROFILE "Local Settings\Application Data\Google\Chrome\User Data\*\"
Collect-Artifact -SourcePath "$UserPath\Visited Links" -FolderName "Chrome_Visited_Links_XP"
# 43. Chrome Web Data XP
$UserPath = Join-Path $env:USERPROFILE "Local Settings\Application Data\Google\Chrome\User Data\*\"
Collect-Artifact -SourcePath "$UserPath\Web Data*" -FolderName "Chrome_Web_Data_XP"
# 44. Chrome bookmarks
$UserPath = Join-Path $env:USERPROFILE "AppData\Local\Google\Chrome\User Data\*\"
Collect-Artifact -SourcePath "$UserPath\Bookmarks*" -FolderName "Chrome_bookmarks"
# 45. Chrome Cookies
$UserPath = Join-Path $env:USERPROFILE "AppData\Local\Google\Chrome\User Data\*\"
Collect-Artifact -SourcePath "$UserPath\Cookies*" -FolderName "Chrome_Cookies"
# 46. Chrome Current Session
$UserPath = Join-Path $env:USERPROFILE "AppData\Local\Google\Chrome\User Data\*\"
Collect-Artifact -SourcePath "$UserPath\Current Session" -FolderName "Chrome_Current_Session"
# 47. Chrome Current Tabs
$UserPath = Join-Path $env:USERPROFILE "AppData\Local\Google\Chrome\User Data\*\"
Collect-Artifact -SourcePath "$UserPath\Current Tabs" -FolderName "Chrome_Current_Tabs"
# 48. Chrome Download Metadata
$UserPath = Join-Path $env:USERPROFILE "AppData\Local\Google\Chrome\User Data\*\"
Collect-Artifact -SourcePath "$UserPath\Download Metadata" -FolderName "Chrome_Download_Metadata"
# 49. Chrome Extension Cookies
$UserPath = Join-Path $env:USERPROFILE "AppData\Local\Google\Chrome\User Data\*\"
Collect-Artifact -SourcePath "$UserPath\Extension Cookies" -FolderName "Chrome_Extension_Cookies"
# 50. Chrome Favicons
$UserPath = Join-Path $env:USERPROFILE "AppData\Local\Google\Chrome\User Data\*\"
Collect-Artifact -SourcePath "$UserPath\Favicons*" -FolderName "Chrome_Favicons"
# 51. Chrome History
$UserPath = Join-Path $env:USERPROFILE "AppData\Local\Google\Chrome\User Data\*\"
Collect-Artifact -SourcePath "$UserPath\History*" -FolderName "Chrome_History"
# 52. Chrome Last Session
$UserPath = Join-Path $env:USERPROFILE "AppData\Local\Google\Chrome\User Data\*\"
Collect-Artifact -SourcePath "$UserPath\Last Session" -FolderName "Chrome_Last_Session"
# 53. Chrome Last Tabs
$UserPath = Join-Path $env:USERPROFILE "AppData\Local\Google\Chrome\User Data\*\"
Collect-Artifact -SourcePath "$UserPath\Last Tabs" -FolderName "Chrome_Last_Tabs"
# 54. Chrome Login Data
$UserPath = Join-Path $env:USERPROFILE "AppData\Local\Google\Chrome\User Data\*\"
Collect-Artifact -SourcePath "$UserPath\Login Data" -FolderName "Chrome_Login_Data"
# 55. Chrome Media History
$UserPath = Join-Path $env:USERPROFILE "AppData\Local\Google\Chrome\User Data\*\"
Collect-Artifact -SourcePath "$UserPath\Media History*" -FolderName "Chrome_Media_History"
# 56. Chrome Network Action Predictor
$UserPath = Join-Path $env:USERPROFILE "AppData\Local\Google\Chrome\User Data\*\"
Collect-Artifact -SourcePath "$UserPath\Network Action Predictor" -FolderName "Chrome_Network_Action_Predictor"
# 57. Chrome Network Persistent State
$UserPath = Join-Path $env:USERPROFILE "AppData\Local\Google\Chrome\User Data\*\"
Collect-Artifact -SourcePath "$UserPath\Network Persistent State" -FolderName "Chrome_Network_Persistent_State"
# 58. Chrome Preferences
$UserPath = Join-Path $env:USERPROFILE "AppData\Local\Google\Chrome\User Data\*\"
Collect-Artifact -SourcePath "$UserPath\Preferences" -FolderName "Chrome_Preferences"
# 59. Chrome Quota Manager
$UserPath = Join-Path $env:USERPROFILE "AppData\Local\Google\Chrome\User Data\*\"
Collect-Artifact -SourcePath "$UserPath\QuotaManager" -FolderName "Chrome_Quota_Manager"
# 60. Chrome Reporting and NEL
$UserPath = Join-Path $env:USERPROFILE "AppData\Local\Google\Chrome\User Data\*\"
Collect-Artifact -SourcePath "$UserPath\Reporting and NEL" -FolderName "Chrome_Reporting_and_NEL"
# 61. Chrome Shortcuts
$UserPath = Join-Path $env:USERPROFILE "AppData\Local\Google\Chrome\User Data\*\"
Collect-Artifact -SourcePath "$UserPath\Shortcuts*" -FolderName "Chrome_Shortcuts"
# 62. Chrome Top Sites
$UserPath = Join-Path $env:USERPROFILE "AppData\Local\Google\Chrome\User Data\*\"
Collect-Artifact -SourcePath "$UserPath\Top Sites*" -FolderName "Chrome_Top_Sites"
# 63. Chrome Trust Tokens
$UserPath = Join-Path $env:USERPROFILE "AppData\Local\Google\Chrome\User Data\*\"
Collect-Artifact -SourcePath "$UserPath\Trust Tokens*" -FolderName "Chrome_Trust_Tokens"
# 64. Chrome SyncData Database
$UserPath = Join-Path $env:USERPROFILE "AppData\Local\Google\Chrome\User Data\*\Sync Data"
Collect-Artifact -SourcePath "$UserPath\SyncData.sqlite3" -FolderName "Chrome_SyncData_Database"
# 65. Chrome Visited Links
$UserPath = Join-Path $env:USERPROFILE "AppData\Local\Google\Chrome\User Data\*\"
Collect-Artifact -SourcePath "$UserPath\Visited Links" -FolderName "Chrome_Visited_Links"
# 66. Chrome Web Data
$UserPath = Join-Path $env:USERPROFILE "AppData\Local\Google\Chrome\User Data\*\"
Collect-Artifact -SourcePath "$UserPath\Web Data*" -FolderName "Chrome_Web_Data"
# 67. Edge bookmarks
$UserPath = Join-Path $env:USERPROFILE "AppData\Local\Microsoft\Edge\User Data\*\"
Collect-Artifact -SourcePath "$UserPath\Bookmarks*" -FolderName "Edge_bookmarks"
# 68. Edge Collections
$UserPath = Join-Path $env:USERPROFILE "AppData\Local\Microsoft\Edge\User Data\*\Collections"
Collect-Artifact -SourcePath "$UserPath\collectionsSQLite" -FolderName "Edge_Collections"
# 69. Edge Cookies
$UserPath = Join-Path $env:USERPROFILE "AppData\Local\Microsoft\Edge\User Data\*\"
Collect-Artifact -SourcePath "$UserPath\Cookies*" -FolderName "Edge_Cookies"
# 70. Edge Current Session
$UserPath = Join-Path $env:USERPROFILE "AppData\Local\Microsoft\Edge\User Data\*\"
Collect-Artifact -SourcePath "$UserPath\Current Session" -FolderName "Edge_Current_Session"
# 71. Edge Current Tabs
$UserPath = Join-Path $env:USERPROFILE "AppData\Local\Microsoft\Edge\User Data\*\"
Collect-Artifact -SourcePath "$UserPath\Current Tabs" -FolderName "Edge_Current_Tabs"
# 72. Edge Favicons
$UserPath = Join-Path $env:USERPROFILE "AppData\Local\Microsoft\Edge\User Data\*\"
Collect-Artifact -SourcePath "$UserPath\Favicons*" -FolderName "Edge_Favicons"
# 73. Edge History
$UserPath = Join-Path $env:USERPROFILE "AppData\Local\Microsoft\Edge\User Data\*\"
Collect-Artifact -SourcePath "$UserPath\History*" -FolderName "Edge_History"
# 74. Edge Last Session
$UserPath = Join-Path $env:USERPROFILE "AppData\Local\Microsoft\Edge\User Data\*\"
Collect-Artifact -SourcePath "$UserPath\Last Session" -FolderName "Edge_Last_Session"
# 75. Edge Last Tabs
$UserPath = Join-Path $env:USERPROFILE "AppData\Local\Microsoft\Edge\User Data\*\"
Collect-Artifact -SourcePath "$UserPath\Last Tabs" -FolderName "Edge_Last_Tabs"
# 76. Edge Login Data
$UserPath = Join-Path $env:USERPROFILE "AppData\Local\Microsoft\Edge\User Data\*\"
Collect-Artifact -SourcePath "$UserPath\Login Data" -FolderName "Edge_Login_Data"
# 77. Edge Media History
$UserPath = Join-Path $env:USERPROFILE "AppData\Local\Microsoft\Edge\User Data\*\"
Collect-Artifact -SourcePath "$UserPath\Media History*" -FolderName "Edge_Media_History"
# 78. Edge Network Action Predictor
$UserPath = Join-Path $env:USERPROFILE "AppData\Local\Microsoft\Edge\User Data\*\"
Collect-Artifact -SourcePath "$UserPath\Network Action Predictor" -FolderName "Edge_Network_Action_Predictor"
# 79. Edge Preferences
$UserPath = Join-Path $env:USERPROFILE "AppData\Local\Microsoft\Edge\User Data\*\"
Collect-Artifact -SourcePath "$UserPath\Preferences" -FolderName "Edge_Preferences"
# 80. Edge Shortcuts
$UserPath = Join-Path $env:USERPROFILE "AppData\Local\Microsoft\Edge\User Data\*\"
Collect-Artifact -SourcePath "$UserPath\Shortcuts*" -FolderName "Edge_Shortcuts"
# 81. Edge Top Sites
$UserPath = Join-Path $env:USERPROFILE "AppData\Local\Microsoft\Edge\User Data\*\"
Collect-Artifact -SourcePath "$UserPath\Top Sites*" -FolderName "Edge_Top_Sites"
# 82. Edge SyncData Database
$UserPath = Join-Path $env:USERPROFILE "AppData\Local\Microsoft\Edge\User Data\*\Sync Data"
Collect-Artifact -SourcePath "$UserPath\SyncData.sqlite3" -FolderName "Edge_SyncData_Database"
# 83. Edge Bookmarks
$UserPath = Join-Path $env:USERPROFILE "AppData\Local\Microsoft\Edge\User Data\*\"
Collect-Artifact -SourcePath "$UserPath\Bookmarks*" -FolderName "Edge_Bookmarks"
# 84. Edge Visited Links
$UserPath = Join-Path $env:USERPROFILE "AppData\Local\Microsoft\Edge\User Data\*\"
Collect-Artifact -SourcePath "$UserPath\Visited Links" -FolderName "Edge_Visited_Links"
# 85. Edge Web Data
$UserPath = Join-Path $env:USERPROFILE "AppData\Local\Microsoft\Edge\User Data\*\"
Collect-Artifact -SourcePath "$UserPath\Web Data*" -FolderName "Edge_Web_Data"
# 86. Addons
$UserPath = Join-Path $env:USERPROFILE "AppData\Roaming\Mozilla\Firefox\Profiles\*\"
Collect-Artifact -SourcePath "$UserPath\addons.sqlite*" -FolderName "Addons"
# 87. Bookmarks
$UserPath = Join-Path $env:USERPROFILE "AppData\Roaming\Mozilla\Firefox\Profiles\*\weave\"
Collect-Artifact -SourcePath "$UserPath\bookmarks.sqlite*" -FolderName "Bookmarks"
# 88. Cookies
$UserPath = Join-Path $env:USERPROFILE "AppData\Roaming\Mozilla\Firefox\Profiles\*\"
Collect-Artifact -SourcePath "$UserPath\cookies.sqlite*" -FolderName "Cookies"
# 89. Cookies
$UserPath = Join-Path $env:USERPROFILE "AppData\Roaming\Mozilla\Firefox\Profiles\*\"
Collect-Artifact -SourcePath "$UserPath\firefox_cookies.sqlite*" -FolderName "Cookies"
# 90. Downloads
$UserPath = Join-Path $env:USERPROFILE "AppData\Roaming\Mozilla\Firefox\Profiles\*\"
Collect-Artifact -SourcePath "$UserPath\downloads.sqlite*" -FolderName "Downloads"
# 91. Favicons
$UserPath = Join-Path $env:USERPROFILE "AppData\Roaming\Mozilla\Firefox\Profiles\*\"
Collect-Artifact -SourcePath "$UserPath\favicons.sqlite*" -FolderName "Favicons"
# 92. Form history
$UserPath = Join-Path $env:USERPROFILE "AppData\Roaming\Mozilla\Firefox\Profiles\*\"
Collect-Artifact -SourcePath "$UserPath\formhistory.sqlite*" -FolderName "Form_history"
# 93. Permissions
$UserPath = Join-Path $env:USERPROFILE "AppData\Roaming\Mozilla\Firefox\Profiles\*\"
Collect-Artifact -SourcePath "$UserPath\permissions.sqlite*" -FolderName "Permissions"
# 94. Places
$UserPath = Join-Path $env:USERPROFILE "AppData\Roaming\Mozilla\Firefox\Profiles\*\"
Collect-Artifact -SourcePath "$UserPath\places.sqlite*" -FolderName "Places"
# 95. Protections
$UserPath = Join-Path $env:USERPROFILE "AppData\Roaming\Mozilla\Firefox\Profiles\*\"
Collect-Artifact -SourcePath "$UserPath\protections.sqlite*" -FolderName "Protections"
# 96. Search
$UserPath = Join-Path $env:USERPROFILE "AppData\Roaming\Mozilla\Firefox\Profiles\*\"
Collect-Artifact -SourcePath "$UserPath\search.sqlite*" -FolderName "Search"
# 97. Signons
$UserPath = Join-Path $env:USERPROFILE "AppData\Roaming\Mozilla\Firefox\Profiles\*\"
Collect-Artifact -SourcePath "$UserPath\signons.sqlite*" -FolderName "Signons"
# 98. Storage Sync
$UserPath = Join-Path $env:USERPROFILE "AppData\Roaming\Mozilla\Firefox\Profiles\*\"
Collect-Artifact -SourcePath "$UserPath\storage-sync.sqlite*" -FolderName "Storage_Sync"
# 99. Webappstore
$UserPath = Join-Path $env:USERPROFILE "AppData\Roaming\Mozilla\Firefox\Profiles\*\"
Collect-Artifact -SourcePath "$UserPath\webappstore.sqlite*" -FolderName "Webappstore"
# 100. Windows 10 Notification DB
$UserPath = Join-Path $env:USERPROFILE "AppData\Local\Microsoft\Windows\Notifications\"
Collect-Artifact -SourcePath "$UserPath\wpndatabase.db" -FolderName "Windows_10_Notification_DB"
# 101. Windows 10 Notification DB
$UserPath = Join-Path $env:USERPROFILE "AppData\Local\Microsoft\Windows\Notifications\"
Collect-Artifact -SourcePath "$UserPath\appdb.dat" -FolderName "Windows_10_Notification_DB"
# 102. ActivitiesCache.db
$UserPath = Join-Path $env:USERPROFILE "AppData\Local\ConnectedDevicesPlatform\*\"
Collect-Artifact -SourcePath "$UserPath\ActivitiesCache.db*" -FolderName "ActivitiesCache_db"
# 103. Update Store.db
Collect-Artifact -SourcePath "C:\ProgramData\USOPrivate\UpdateStore\store.db" -FolderName "Update_Store_db"
# 104. Bitdefender SQLite DB Files
Collect-Artifact -SourcePath "C:\Program Files*\Bitdefender*\\regex:*.+\.(db|db-wal|db-shm)" -FolderName "Bitdefender_SQLite_DB_Files"
# 105. EventTranscript.db
Collect-Artifact -SourcePath "C:\ProgramData\Microsoft\Diagnosis\EventTranscript\EventTranscript.db*" -FolderName "EventTranscript_db"
# 106. EventTranscript.db
Collect-Artifact -SourcePath "C:\Windows.old\ProgramData\Microsoft\Diagnosis\EventTranscript\EventTranscript.db*" -FolderName "EventTranscript_db"
Write-Host "Collection complete!" -ForegroundColor Green› Save as .ps1 and run as Administrator. Use: powershell -ExecutionPolicy Bypass -File script.ps1
Open in CyberChef to decode values extracted from this artifact.