Skip to content

@kacos2000 kacos2000 released this Dec 12, 2019 · 1 commit to master since this release

minor fixes

Assets 3
Dec 1, 2019
Update README.md

@kacos2000 kacos2000 released this Dec 4, 2019 · 3 commits to master since this release

Works with any ActivitiesCache.db (Windows 1803/1809/1903/1909 ..)

  • Decodes Clipboard Text
  • Matches ActivitiesCache.db PlatformDeviceId's with device information (DeviceType, Name,Make,Model) from the registry (HKCU or NTuser.dat) at "\Software\Microsoft\Windows\CurrentVersion\TaskFlow\DeviceCache"
  • Shows all the important information from JSON blobs ..
  • Optionally exports output to "|" delimited .csv in a timestamped folder in the form of "WindowsTimeline_dd-MMM-yyyyTHH-mm-ss".
  • Added '.CDP' file viewer.

Parses:

  • Standalone ActivitiesCache.db
  • CurrentUser's selected ActivitiesCache.db with matching registry (HKCU) device entries
  • Standalone ActivitiesCache.db with offline NTUser.dat device entries
  • Reads CDP files from the Parent 'ConnectedDevicesPlatform' folder

Note1: Requires "System.Data.SQLite". If not available, it will download and install automatically.
Note2: Runs on Windows 10 x64

Assets 3
Dec 1, 2019
CDP Viewer
You can’t perform that action at this time.