Designing and Validating a Forensic Evaluation Model for Selective Seizure Capabilities in Windows Forensic Tools
Abstract
1. Introduction
2. Related Work
3. Evaluation Model and Dataset Development
3.1. Evaluation Model Design
- Tools must be portable, field-ready, feature a GUI, and be easy to use.
- Tools must include functions for collecting case-relevant files in the field.
- Tools must be able to analyze various logs.
- Tools should support result verification and reporting.
3.2. Evaluation Metrics Model Design
- s{p,i}(T) = 3 if the tool fully satisfies all verification criteria (O);
- s{p,i}(T) = 2 if three or more criteria are satisfied (□);
- s{p,i}(T) = 1 if criteria are partially satisfied with manual intervention (△);
- s{p,i}(T) = 0 if the criteria are not satisfied (-).
3.3. Dataset Development
4. Results and Discussion
4.1. Search Phase
4.1.1. NTFS Parsing
4.1.2. File- and Folder Access Log Analysis
4.1.3. Application Execution Log Analysis
4.1.4. Data-Transmission Log Analysis
4.1.5. Internet Search Log Analysis
4.1.6. Suspicious Activity Log Analysis
4.2. Data Acquisition Phase
4.2.1. File and Folder Name Search
4.2.2. Keyword Search
4.2.3. File Header Classification
4.2.4. DRM File Identification
4.2.5. Encrypted File Identification
4.2.6. File Preview
4.3. Seizure Phase
4.3.1. File and Folder Name Search
4.3.2. Extraction Evaluation
4.4. SSI Evaluation
4.5. Discussion
5. Conclusions
Author Contributions
Funding
Data Availability Statement
Institutional Review Board Statementt
Informed Consent Statement
Conflicts of Interest
References
- G. O. Presidential Decree, Republic of Korea. Regulations on Mutual Cooperation Between Prosecutors and Judicial Police Officers and General Investigative Principles, Article 41, Paragraphs 1, 2, 3. 1 November 2023. Available online: https://www.law.go.kr/lsInfoP.do?ancYnChk=0&lsId=013871 (accessed on 26 February 2026).
- Desktop Windows Version Market Share Republic of Korea. StatCounter Global Stats. Available online: https://gs.statcounter.com/windows-version-market-share/desktop/south-korea (accessed on 26 February 2026).
- Computer Forensics Tools & Techniques Catalog-Tool Search. Available online: https://toolcatalog.nist.gov/search/ (accessed on 26 February 2026).
- Desktop Hypervisor Solutions|VMware. Available online: https://www.vmware.com/products/desktop-hypervisor/workstation-and-fusion (accessed on 26 February 2026).
- Lee, S.Y. A Proposal to Establish an Independent Analysis Institution in Digital Evidence Seizure and Search. Comp. Crim. Law Rev. (Bijogyo Hyeongsa Beom Yeongu) 2025, 27, 193–239. [Google Scholar] [CrossRef]
- Lee, H. A Study on the Transfer of Irrelevant Information and the Seizure of Unrelated Information. Master’s Thesis, Seoul Nat’l University, Seoul, Republic of Korea, 2025. [Google Scholar]
- Lee, S.Y. A Study on Digital Evidence Screening Based on Metadata Similarity. Master’s Thesis, Sungkyunkwan University, Seoul, Republic of Korea, 2024. [Google Scholar]
- Cheon, S. A Study on Improvement Measures for Efficient On-Site Selective Seizure and Search of Digital Information: Focusing on the Analysis of Keyword Search Time and the Possibility of Metadata Modification. Ph.D. Thesis, Sungkyunkwan University, Seoul, Republic of Korea, 2024. [Google Scholar]
- Oh, J. A Study on Problems and Improvement Measures Following the Conceptual Shift in Selective Seizure of Digital Evidence. Master’s Thesis, Seoul Nat’l University, Seoul, Republic of Korea, 2023. [Google Scholar]
- Heo, J. A Study on Problems in Selective Seizure of Digital Evidence and Efficient Seizure Measures. Master’s Thesis, Seoul Nat’l University, Seoul, Republic of Korea, 2023. [Google Scholar]
- Kim, Y. A Study on Issues with the ‘On-Site’ and ‘Selective’ Principles in Search and Seizure of Digital (Electronic) Evidence and Technical/Legal Improvement Measures: Focusing on the Need to Amend Article 106(3) of the Criminal Procedure Act. Master’s Thesis, Seoul Nat’l University, Seoul, Republic of Korea, 2022. [Google Scholar]
- Yoon, S.; Lee, S. A study on digital evidence automatic screening system. J. Digit. Forensics KDFS 2020, 14, 239–251. [Google Scholar]
- Cho, G. A digital forensic analysis for directory in Windows file system. J. Korea Soc. Digit. Ind. Inf. Manag. 2015, 11, 73–90. [Google Scholar] [CrossRef] [Scilit]
- Shin, Y. A Study on Field Detection Techniques for Non-Searchable Email Attachments. Master’s Thesis, Seoul National University, Seoul, Republic of Korea, 2019. [Google Scholar]
- Lee, T.-R.; Shin, S.-U. Reliability verification of evidence analysis tools for digital forensics. J. Korea Inst. Inf. Secur. Cryptol. 2011, 21, 165–176. [Google Scholar]
- Ham, J.; Joshua, I.J. A study on the comparison of modern digital forensic imaging software tools. J. Korean Inst. Internet Broadcast. Commun. 2019, 19, 15–20. [Google Scholar]
- Park, S.; Hur, G.; Lee, S. Development of a set of data for verifying partition recovery tool and evaluation of recovery tool. J. Korea Inst. Inf. Secur. Cryptol. 2017, 27, 1397–1404. [Google Scholar]
- Quick, D.; Choo, K.-K.R. Big forensic data reduction: Digital forensic images and electronic evidence. Clust. Comput. 2016, 19, 723–740. [Google Scholar] [CrossRef] [Scilit]
- Kim, M.-S.; Lee, S. Development of Windows forensic tool for verifying a set of data. J. Korea Inst. Inf. Secur. Cryptol. 2015, 25, 1421–1433. [Google Scholar] [CrossRef] [Scilit]
- Lee, D. A Quality Evaluation Model Based on ISO/IEC 9126 for Digital Forensic Tools. Master’s Thesis, Soongsil University, Seoul, Republic of Korea, 2015. [Google Scholar]
- Park, J.; Lyle, J.R.; Guttman, B. Introduction to the NIST digital forensic tool verification system. Rev. KIISC 2016, 26, 54–61. [Google Scholar]
- CFReDS Portal. Available online: https://cfreds.nist.gov/ (accessed on 26 February 2026).
- Hosting Various Seminars Related to Digital Forensics from 2001 to the Present, DFRWS. Available online: https://dfrws.org/ (accessed on 26 February 2026).
- National Institute of Standards and Technology (NIST). Computer Forensics Tool Testing (CFTT) Program. Available online: https://www.nist.gov/itl/ssd/software-quality-group/computer-forensics-tool-testing-program-cftt (accessed on 4 March 2026).
- National Institute of Standards and Technology (NIST). Computer Forensic Reference Data Sets (CFReDS). Available online: https://www.nist.gov/programs-projects/computer-forensic-reference-data-sets (accessed on 4 March 2026).
- Private Qualification Information Service (PQI). Digital Forensics Expert Qualification Exam: Issuing Body—Korea Forensic Society; Co-Issuing Body—Korea Internet & Security Agency (KISA). Available online: https://www.pqi.or.kr/inf/qul/infQulBasDetail.do?qulId=2672 (accessed on 4 March 2026).
- Korea Forensic Society. Digital Forensics Expert Qualification Exam Portal. Available online: https://exam.forensickorea.org/web/main.do (accessed on 4 March 2026).
- Hitchcock, B.; Le-Khac, N.-A.; Scanlon, M. Tiered forensic methodology model for Digital Field Triage by non-digital evidence specialists. Digit. Investig. 2016, 16, S75–S85. [Google Scholar] [CrossRef] [Scilit]
- Rogers, M.K.; Goldman, J.; Mislan, R.; Wedge, T.; Debrota, S. Computer Forensics Field Triage Process Model. J. Digit. Forensics Secur. Law 2006, 1. [Google Scholar] [CrossRef] [Scilit]
- Horsman, G.; Lyle, J.R. Dataset construction challenges for digital forensics. Forensic Sci. Int. Digit. Investig. 2021, 38, 301264. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Stoykova, R.; Franke, K. Reliability validation enabling framework (RVEF) for digital forensics in criminal investigations. Forensic Sci. Int. Digit. Investig. 2023, 45, 301554. [Google Scholar] [CrossRef] [Scilit]
- ISO/IEC 27037:2012; Information Technology—Security Techniques—Guidelines for Identification, Collection, Acquisition and Preservation of Digital Evidence. ISO/IEC: Geneva, Switzerland, 2012. Available online: https://www.iso.org/standard/44381.html (accessed on 4 March 2026).
- ISO/IEC 27042:2015; Information Technology—Security Techniques—Guidelines for the Analysis and Interpretation of Digital Evidence. ISO/IEC: Geneva, Switzerland, 2015. Available online: https://www.iso.org/standard/44406.html (accessed on 4 March 2026).
- Domingues, P.; Frade, M.; Negrão, M. Digital Forensic Artifacts of FIDO2 Passkeys in Windows 11. In Proceedings of the 19th International Conference on Availability, Reliability and Security (ARES’24), Vienna, Austria, 30 July–2 August 2024; pp. 1–10. [Google Scholar]
- Plum, J.; Dewald, A. Forensic APFS File Recovery. In Proceedings of the 13th International Conference on Availability, Reliability and Security (ARES’18), Hamburg, Germany, 27 August 2018; pp. 1–10. [Google Scholar]
- Herman, M.; Iorga, M.; Salim, A.M.; Jackson, R.H.; Hurst, M.R.; Leo, R.; Lee, R.; Landreville, N.M.; Mishra, A.K.; Wang, Y.; et al. NIST Cloud Computing Forensic Science Challenges; NIST Interagency/Internal Report (NIST IR) 8006; NIST: Gaithersburg, MD, USA, 2020; pp. 1–87.
- Chung, H.; Park, J.; Lee, S.; Kang, C. Digital forensic investigation of cloud storage services. Digit. Investig. 2012, 9, 81–95. [Google Scholar] [CrossRef] [Scilit]


| No. | Category | Project/Research | Format |
|---|---|---|---|
| 1 | Institution | Computer Forensic Reference Dataset (CFReDS) Project | E01, DD |
| 2 | Computer Forensic Tool Testing Project | E01, DD | |
| 3 | Digital Forensic Tool Testing (DFTT) | DD | |
| 4 | Naval Postgraduate School Digital Forensics Corpus (NPS Corpora) | File Dump, E01, DD, packet dump File | |
| 5 | ForensicKB | E01, DD, File | |
| 6 | Prior Research | ISO/IEC 9126-based Quality Evaluation Model for Digital Forensic Tools | Live |
| 7 | Reliability Evaluation through Verification of the Analytical Functions of Computer Forensic Tools | DD | |
| 8 | Development of a Verification Dataset for Windows Forensic Tools | VMDK | |
| 9 | Configuration of a Computer Forensic Tool Verification Image Suitable for Domestic Environments | ||
| 10 | Reliability Verification of Evidence Analysis Tools for Digital Forensics | E01, DD, File |
| Numbers | Verification Requirements |
|---|---|
| 1 | Recognizes the specified file system and analyzes the metadata. |
| 2 | Recognizes and analyzes all files registered in the file system. |
| 3 | Analyze accurate time information for all files and folders. |
| 4 | Recognizes and processes fragmented files. |
| 5 | Recognizes and analyzes all files and folders registered in the GUID partition. |
| 6 | Handles and recognizes incorrect partition information. |
| 7 | Shows the location on the digital source for all files. |
| 8 | Detects hidden partitions and recognizes all files and folders. |
| 9 | Analytical tools provide data extraction and analysis functions for evidence media to identify evidence. |
| 10 | Analysis tool functions always output the same results when the same input data is given in the same environment. |
| 11 | Analysis tool functions keep input data revisions to a minimum and report modifications when they occur. |
| 12 | The analysis tool supports at least one file system and accurately recognizes the file systems and metadata supported by the tool. |
| 13 | The analysis tool records a log of events performed. |
| 14 | Analysis tool functions report errors that occurred during execution. |
| Numbers | Verification Requirements |
|---|---|
| 1 | The results of considering the query are the same as the three matching the query. |
| 2 | Navigation is possible with one or more character encodings. |
| 3 | You can explore strings in Slack space. |
| 4 | If you specify a specific area within the evidence disk as the search range, results are output only at that point. |
| 5 | You can use regular expressions to navigate. |
| 6 | You can search with Hash Set (Hash Set). |
| 7 | You can explore the full spectrum of digital sources. (including slack, parity, deleted areas, and between files) |
| 8 | You can extract any file from a supported file system. |
| 9 | If a reorganization-related error occurs while extracting a file, an error report is possible. |
| 10 | The collected files are collected to the original. |
| 11 | When extracting a file, unreadable parts are potentially as extractable data. |
| 12 | Users are considering when storage space is low. |
| 13 | Korean language support is available. |
| 14 | Invented the file system information contained in the validation data. |
| 15 | Preserves hash values (minimum MD5, SHA 1) for all files included in validation data. |
| 16 | Combating the fragmentation status and count of some of the files included in the validation data. |
| 17 | Validates keyword searches in the NTFS file system. |
| 18 | Validates the ability to extract data from NTFS deleted files. |
| 19 | Verify the NTFS automatic detection feature. |
| 20 | Verify the data extraction function in the basic data carving function. |
| 21 | If a subset of the string search function is specified, results are output only from that subset. |
| 22 | A limit on the number of matches is applied when searching for sorted/unsorted subsets in a string search. |
| 23 | The screen is displayed according to the specified text direction. |
| 24 | Synonym search is supported. |
| 25 | When performing a fuzzy search, it must match a close misspelling (close misspelling) in the query string. |
| 26 | When performing a phonetic search (phonetic search), it must match words pronounced the same as the query string. |
| 27 | If you provide a predefined query, the response returned must be the same set of matches for the query. |
| 28 | It must support logical operations such as And, or, and not. |
| 29 | Analytical tools should provide data extraction and analysis capabilities to identify evidence. |
| 30 | You must be able to browse regardless of capitalization. |
| Numbers | Verification Content |
|---|---|
| 1 | Log file analysis must be able to recognize at least one or more log file formats and provide a function to search and filter desired events. |
| 2 | It is necessary to be able to analyze time information on internal data according to the environment in which the original was created. |
| 3 | System/user settings information analysis must be able to analyze information about the operating system, information about users, and information about installed applications. |
| 4 | Log file analysis must be able to accurately recognize and report on various log file formats through documentation provided by the tool (including usage, purpose, operating mechanism, and system requirements). |
| Numbers | Verification Content |
|---|---|
| 1 | The deleted file recovery function must support the recovery function in a file system confirmed by documents provided by the tool (a set of materials describing usage, purpose, operation, system requirements, etc.). |
| 2 | The deleted file recovery function must identify all deleted file system objects that can be recovered from metadata maintained after the file system object has been deleted. |
| 3 | The deleted file recovery function must report errors that occurred in constructing recovered objects. |
| 4 | The deleted file recovery function must configure a recovered object for each deleted file system object from the remaining metadata. |
| 5 | Each recovered object must include all unallocated data blocks identified in the remaining metadata. |
| 6 | Each recovered object must consist only of data blocks from the deleted block pool. |
| 7 | If the deleted file recovery function generates estimated content, the recovered object must be composed of data blocks from the original file system object identified in the remaining metadata. |
| 8 | If the deleted file recovery function generates estimated content, any data blocks in the recovered object must be organized in the same logical order as the original file system object identified in the remaining metadata. |
| 9 | If the deleted file recovery function generates estimated content, the recovered object must consist of the same number of blocks as the original file system object. |
| 10 | Verify the FAT deleted file extraction function. |
| 11 | Verify the NTFS deleted file extraction function. |
| 12 | Verify the basic data carving function. |
| Numbers | Verification Content |
|---|---|
| 1 | The analysis tool must output the results of the analysis performed in the form of a report. |
| 2 | The hash values of all files belonging to the verification data are preserved. At this time, the hash function uses at least MD5 and SHA1. |
| 3 | Analysis tool functions must always output the same results when given the same input data in the same environment. |
| 4 | Timeline analysis must be able to extract information such as creation, modification, access time, and ownership of a file through MAC (modified, modified, change of status) time analysis and must be able to sort and list in chronological order using this information. |
| 5 | Analysis tool functions must report errors that occurred during execution. |
| No. | Phase | Evaluation Item |
|---|---|---|
| 1 | Search |
|
| 2 | Select |
|
| 3 | Seizure |
|
| No. | Category | Tool Name | Based on the Latest Versions (23.11) | Release and First Version |
|---|---|---|---|---|
| 1 | Commercial | Magnet Outrider | 4.0 | 2019 |
| 2 | Non-commercial | Autopsy | 4.19.3 | 2010 |
| 3 | Commercial | X-Ways | 20.9 | 1995 |
| 4 | Commercial | OS Forensic Professional and Bootable Edition | 10.0.1016 | 2011 |
| 5 | Commercial | DFAS Pro | 1.2.2.14 | 2011 |
| 6 | Commercial | Belkasoft Triage | 1.3.13723 | 2021 |
| Symbol | Description |
|---|---|
| O | Meets all details of the verification items |
| □ | Meets three or more details of the verification items |
| △ | Meets three or more details of the verification items but requires manual analysis |
| - | Does not meet any detail of the verification items |
| No. | Type | Specifications | |
|---|---|---|---|
| 1 | Laptop | CPU | Intel Core i5-1035G4 CPU @ 1.10 GHz 1.50 GHz |
| RAM/HDD | 8 GB/Mtros SSD NVMe M.2 | ||
| 2 | Virtual Machine | Windows | Windows 10 PRO 64-bit 22H2 NTFS configuration |
| Version | VMware Workstation PRO 17.5 | ||
| CPU/RAM | 4 Core/4 GB | ||
| Phase | Parameter | Description | |
|---|---|---|---|
| Search | Portable | Verify the execution and automated analysis functionality of the portable GUI-based tool selection. | |
| BitLocker identification and support for decryption after entering the password | Verify support for recognizing BitLocker-encrypted partitions on Windows and unlocking and decrypting them after entering the recovery key or password. | ||
| Partition damage | Verify support for recovering deleted or damaged partitions, master boot record (MBR), GUID partition table (GPT) (MFT, volume boot record (VBR)). | ||
| $MFT analysis | Verify support for recognizing NTFS and parsing $MFT. ($MFT structure parsing, size information). | ||
| $MFT attribute timestamp analysis ($SI, $FN) | Verify recognition of $MFT and support for file-information and metadata analysis. ($SI creation, modification, access, MFT modification, attribute flag information, $FI parent directory file reference address, creation, modification, access, MFT modification, file allocated size, actual file size, attribute flag, name length, name type, name information support). | ||
| $MFT deletion | Verify deleted record information in $MFT entries. (Unallocated file, file name, creation, modification, access). | ||
| JumpList | Verify document file-access records. (Analysis count, file name, link creation, link modification, link access, target creation, target modification, target access, volume name, volume S/N, size, path, original path). | ||
| Link file | Verify document file-access records. (Analysis count, file name, link creation, link modification, link access, target creation, target modification, target access, volume name, volume S/N, size, path, original path). | ||
| Shellbag MRU | Verify folder access records. (Analysis count, folder name, visit time, creation time, access time, modification time, path, original path). | ||
| ActivitesCache.db | Verify document file-access records. (Analysis count, display text, last modification time, app ID, path, original path). | ||
| Windows.edb | Verify document file records. (Document count, file name, creation, modification, file type, file path, content, original path). | ||
| Volume shadow | Verify backup records of three documents. (Analysis count, file name, creation time, original path). | ||
| $Logfile | Verify document file records. (Analysis count, events, original path). | ||
| $UsnJrul | Verify document file records. (Analysis count, events, original path). | ||
| Thumbnail.db | Verify thumbnail cache image file records. (Image name, original path). | ||
| $Recycle.bin | Verify records of deleted files. (File count, $R, $I). | ||
| Prefetch | Verify records of executed programs. (Analysis count, program name, execution time, execution count, path, original path). | ||
| Program execution | Verify records of executed programs. (Analysis count, program name, execution time, execution count, user, path, original path). | ||
| AmCache | Verify record of the executed program. (Key time, key name, name, publisher, size, original path). | ||
| SRUMDB | Verify resource-usage records of executed programs. (Creation time, program, original source). | ||
| External storage device | Registry | Verify external storage device records. (Model name, first connection time, last connection time, disconnection time, serial number, volume name, original path). | |
| Setupapi.log | Verify external storage device records. (Model name, first connection time, original path). | ||
| EventLog | Verify external storage device records. (Event ID, connection/disconnection time, device information, original path). | ||
| Network connection | Wireless | Verify wireless network records. (Network name, last connection time, original path). | |
| Wired | Verify wired-network records. (Adapter name, IP, subnet mask, DHCP, original path). | ||
| Web browser (Chrome, Edge, Whale) | Web Access | Verify internet-access records. (Analysis count, accessed website, access time, original path). | |
| Search Terms | Verify web search term records. (Analysis count, search terms, access time, original path). | ||
| Downloads | Verify records of files downloaded from the internet. (Analysis count, website, downloaded file, download time, original path). | ||
| Passwords | Verify saved web ID/password records. (Save count, creation time, website, original path). | ||
| Cache | Verify web-cache file records. (Analysis count, cache file, access time, website, original path). | ||
| Cookies | Verify internet cookie records. (Analysis count, cookie file, access time, website, original path). | ||
| EventLog | System ON/OFF | Verify system ON/OFF records. (ON time, OFF time, computer name, EventID, original path). | |
| User Account Changes | Verify system user account change information. (Account name, event time, EventID, original path). | ||
| System Time Changes | Verify system time change information. (Previous time, new time, user ID, EventID, original path). | ||
| Select | File name search | Verify search of Korean file names. “Network Diagram.pptx, Risk Burden.pdf, Office Lease Contract.hwp” Verify support for logical operators AND, OR. Verify support for regular-expression searches. “Forensic[, -]Science, Sungkyunkwan [0–9가-힣] University, http://www\.[가-힣]+\.com, C:\\Images\\KakaoTalk\\.gif, 02[-) ]*3290-1212”. | |
| Keyword analysis | Verify search for keywords “forensics, digital forensics, selection, tools, Sungkyunkwan University” in document file extensions. (cell, csv, doc, docx, hwp, hwpx, pdf, pptx, rtf, show, txt, xls, xlsx). | ||
| File header identification | Documents | cell, csv, doc, docx, hwp, hwpx, pdf, pptx, rtf, show, txt, xls, xlsx. | |
| Digital Rights Management (DRM) | Verify the identification of Fasoo, SoftCamp, and Markany. | ||
| Encrypted Files | Verify the identification of doc, docx, hwp, ppt, pptx, 7z, tar, and zip. | ||
| Preview | Documents | cell, csv, doc, docx, hwp, hwpx, pdf, pptx, rtf, show, txt, xls, xlsx. | |
| Compound Files | Verify the identification of pst, ost, sqlite, db, 7z, zip, tar, egg, and rar. | ||
| Images | Verify the identification of awd, psd, dwg, bmp, png, psp, jpeg, and jpg. | ||
| Seizure | Logical image | Verify support for logical image acquisition. | |
| Physical image | Verify support for physical image acquisition. | ||
| Memory collection | Verify support for memory-dump collection. | ||
| Report | Verify the generation of a report for logical image acquisition (file name, path). | ||
| Hash verification | Verify the inclusion of hash information in the report and support for calculating at least two hashes. | ||
| Error handling log | Support for logging errors occurring in the tool and other logs. | ||
| Verification Item | File Name | File Size | File Hash Value (MD5, SHA1) |
|---|---|---|---|
| Search | MBR-000002.vmdk | 17 GB | d666ad43460de6f9955e4e045b10ba8e 54608a7ea3437e3ea6952b5722cfe4baa52fa2da |
| Basic Sample Machine-cl1.vmdk | 22.9 GB | 62ac1cfdea9a1d3b13395c6eb9c9ecc8 e3e33f24909b56a5fc57491b17621310d8a76a66 | |
| Search, Select | Windows 10 ×64 (1). vmdk | 61.9 GB | d666ad43460de6f9955e4e045b10ba8e 54608a7ea3437e3ea6952b5722cfe4baa52fa2da |
| Seizure | Basic Sample Machine-cl1.vmdk | 25.3 GB | b11f85b705402c86cce19ea3ee8dec0b f2925883e67c719f01ae57762d82cd8699a1d206 |
| No. | Evaluation Item | Tool | |||||
|---|---|---|---|---|---|---|---|
| A | B ** | C * | D | E | F | ||
| 1 | BitLocker Support | - | - | - | O | - | - |
| 2 | $MFT Analysis | O | O | O | O | O | O |
| 3 | $MFT Recognition | - | O | □ | □ | □ | - |
| 4 | MBR (VBR) Damage | - | - | - | O | - | - |
| 5 | MBR (MFT) Partition Deletion | - | O | O | - | - | - |
| 6 | GPT (VBR) Damage | - | - | O | - | - | - |
| 7 | GPT (MFT) Partition Deletion | - | - | O | - | - | - |
| 8 | MFT File Deletion | - | O | O | - | O | - |
| No. | Evaluation Item | Tool | |||||
|---|---|---|---|---|---|---|---|
| A | B | C | D ** | E * | F | ||
| 1 | JumpList | - | - | △ | □ | □ | - |
| 2 | Link File | □ | □ * | △ | O | □ | □ |
| 3 | Shellbag MRU | - | □ | △ | □ | O | - |
| 4 | ActivitesCache.db | - | □ | - | O | O | - |
| 5 | Windows.edb | - | - | - | - | O | - |
| 6 | Volume Shadow | - | - | △ | - | - | - |
| 7 | $Logfile | - | - | - | - | O | - |
| 8 | $UsnJrul | - | - | - | - | O | - |
| 9 | Thumbnail.db | - | - | - | O | O | - |
| 10 | $Recycle.bin | - | O | O | - | O | - |
| No. | Evaluation Item | Tool | |||||
|---|---|---|---|---|---|---|---|
| A | B | C | D ** | E * | F | ||
| 1 | Prefetch | □ | O | △ | O | O | □ |
| 2 | Program Execution | - | - | △ | O | O | - |
| 3 | AmCache | - | △ | △ | O | O | - |
| 4 | SRUMDB | - | □ | △ | - | O | - |
| No. | Evaluation Item | Details | Tool | |||||
|---|---|---|---|---|---|---|---|---|
| A | B | C * | D | E ** | F | |||
| 1 | Network Connection | Wireless | - | - | △ | O | O | - |
| 2 | Wired | - | - | △ | - | O | - | |
| 3 | External Storage Device | Registry | - | O | △ | O | O | - |
| 4 | Event Log | - | - | △ | O | - | - | |
| 5 | Setup.API | - | - | △ | △ | O | - | |
| 6 | AmCache | - | △ | △ | O | O | - | |
| No. | Browser | Evaluation Item | Tool | |||||
|---|---|---|---|---|---|---|---|---|
| A | B | C ** | D | E * | F | |||
| 1 | Google Chrome | Web Access | - | O | △ | O | O | - |
| 2 | Search Terms | - | O | △ | O | O | - | |
| 3 | Downloads | - | O | △ | O | O | - | |
| 4 | Passwords | - | - | - | - | - | - | |
| 5 | Cache | - | O | △ | - | O | - | |
| 6 | Cookies | - | O | △ | - | O | - | |
| 7 | Microsoft Edge | Web Access | - | O | - | O | O | - |
| 8 | Search Terms | - | O | - | O | O | - | |
| 9 | Downloads | - | O | - | O | O | - | |
| 10 | Passwords | - | - | - | O | O | - | |
| 11 | Cache | - | O | - | - | O | - | |
| 12 | Cookies | - | O | - | - | O | - | |
| 13 | Naver Whale | Web Access | - | - | - | - | O | - |
| 14 | Search Terms | - | - | - | - | O | - | |
| 15 | Downloads | - | - | - | - | O | - | |
| 16 | Passwords | - | - | - | - | - | - | |
| 17 | Cache | - | - | - | - | O | - | |
| 18 | Cookies | - | - | - | - | O | - | |
| No. | Evaluation Item | Tool | |||||
|---|---|---|---|---|---|---|---|
| A | B | C * | D ** | E ** | F | ||
| 1 | System ON/OFF | - | - | △ | O | O | - |
| 2 | User Account Changes | - | - | △ | - | - | - |
| 3 | System Time Changes | - | - | △ | - | - | - |
| No. | Evaluation Item | Tool | |||||
|---|---|---|---|---|---|---|---|
| A | B | C * | D | E ** | F | ||
| 1 | File Name | - | O | O | O | O | - |
| 2 | Folder Name | - | - | O | - | - | - |
| 3 | Regular Expression | - | - | - | - | □ | - |
| No. | File Type | Tool | |||||
|---|---|---|---|---|---|---|---|
| A | B | C ** | D | E * | F | ||
| 1 | cell | - | □ | O | - | O | - |
| 2 | csv | - | O | O | - | O | - |
| 3 | doc | - 1 hit | - 2 hits | O | - | O | - |
| 4 | docx | - 1 hit | - 2 hits | O | - | O | - |
| 5 | hwp | - | O | O | - | O | - |
| 6 | hwpx | - | - | - | - | O | - |
| 7 | - | O | O | - | O | - | |
| 8 | ppt | - 1 hit | O | O | - | O | - |
| 9 | pptx | □ | O | - | O | - | |
| 10 | rtf | - 1 hit | - 2 hits | - | - | O | - |
| 11 | show | - | □ | - | - | O | - |
| 12 | txt | - | □ | O | - | O | - |
| 13 | xls | - | O | O | - | O | - |
| 14 | xlsx | - | O | O | - | O | - |
| No. | File Type | Tool | |||||
|---|---|---|---|---|---|---|---|
| A | B * | C * | D | E ** | F | ||
| 1 | cell | - | - | - | - | O | - |
| 2 | csv | - | - | O | - | - | - |
| 3 | doc | - | O | O | - | - | - |
| 4 | docx | - | O | O | - | O | - |
| 5 | hwp | - | O | O | - | O | - |
| 6 | hwpx | - | - | - | - | O | - |
| 7 | - | O | O | O | O | - | |
| 8 | ppt | - | O | O | - | - | |
| 9 | pptx | - | O | O | - | - | |
| 10 | rtf | - | O | O | - | 0 | - |
| 11 | show | - | - | - | - | - | - |
| 12 | txt | - | O | - | O | - | - |
| 13 | xls | - | O | O | - | O | - |
| 14 | xlsx | - | O | O | - | - | - |
| No. | Software | Tool | |||||
|---|---|---|---|---|---|---|---|
| A | B | C | D | E * | F | ||
| 1 | Fasoo | - | - | - | - | - | - |
| 2 | - | - | - | - | - | - | |
| 3 | - | - | - | - | - | - | |
| 4 | Softcamp | - | - | - | - | O | - |
| 5 | - | - | - | - | - | - | |
| 6 | - | - | - | - | - | - | |
| 7 | Markany | - | - | - | - | O | - |
| 8 | - | - | - | - | O | - | |
| 9 | - | - | - | - | O | - | |
| 10 | - | - | - | - | O | - | |
| No. | File Type | Tool | |||||
|---|---|---|---|---|---|---|---|
| A | B ** | C | D | E * | F | ||
| 1 | doc | - | O | - | - | O | - |
| 2 | docx | - | O | O | - | O | - |
| 3 | hwp | - | - | - | - | O | - |
| 4 | ppt | - | - | - | - | O | - |
| 5 | pptx | - | O | O | - | O | - |
| 6 | 7z | - | O | - | - | - | - |
| 7 | tar | - | - | - | - | - | - |
| 8 | zip | - | O | - | - | O | - |
| No. | Evaluation Item | File Type | Tool | |||||
|---|---|---|---|---|---|---|---|---|
| A | B ** | C * | D | E | F | |||
| 1 | Document Files | cell | - | - | O | - | - | - |
| 2 | csv | - | O | O | - | - | - | |
| 3 | doc | - | O | O | - | - | - | |
| 4 | docx | - | O | O | - | - | - | |
| 5 | hwp | - | O | O | - | - | - | |
| 6 | hwpx | - | - | - | - | - | - | |
| 7 | - | O | O | - | - | - | ||
| 8 | ppt | - | O | O | - | - | - | |
| 9 | pptx | - | O | O | - | - | - | |
| 10 | rtf | - | O | O | - | - | - | |
| 11 | show | - | O | O | - | - | - | |
| 12 | txt | - | O | O | - | - | - | |
| 13 | xls | - | O | O | O | - | - | |
| 14 | xlsx | - | O | O | - | - | - | |
| 15 | Compound Files | pst | - | O | O | O | O | - |
| 16 | ost | - | O | O | O | O | - | |
| 17 | sqlite | - | O | - | - | O | - | |
| 18 | db | - | O | - | - | O | - | |
| 19 | 7z | - | - | O | O | - | - | |
| 20 | zip | - | - | O | O | - | - | |
| 21 | Tar | - | - | O | O | - | - | |
| 22 | egg | - | - | O | - | - | - | |
| 23 | rar | - | - | O | O | - | - | |
| 24 | Image Files (EXIF Support) | awd | - | - | O | - | O | - |
| 25 | psd | - | O | O | - | O | - | |
| 26 | dwg | - | - | O | - | O | - | |
| 27 | bmp | - | O | O exif | O exif | O | - | |
| 28 | png | - | O exif | O exif | O exif | O exif | - | |
| 29 | psp | - | - | O exif | O exif | - | - | |
| 30 | jpeg | - | - | O exif | O exif | O exif | - | |
| 31 | jpg | - | O exif | O exif | O exif | O exif | - | |
| No. | Evaluation Item | Details | Tool | |||||
|---|---|---|---|---|---|---|---|---|
| A | B | C * | D | E ** | F | |||
| 1 | Logical Image | Image Format | - | - | O ctr | O vhd | O zip, dd | - |
| 2 | Report | - | - | - | O Save Error | O csv, txt | - | |
| 3 | Time Taken for 200,000 Files | - | - | 13 min | 180 min | 34 min | - | |
| 4 | Memory Dump | Image Format | O bin | - | - | - | O raw | O mem |
| 5 | Report | - | - | - | - | - | - | |
| 6 | Physical Image | Image Format | - | - | O | O | O | - |
| 7 | Report | - | - | O txt | O txt | O txt | - | |
| No. | Item | Tool | |||||
|---|---|---|---|---|---|---|---|
| A | B ** | C | D | E * | F | ||
| 1 | Report Support | O | O | O | O | O | O |
| 2 | Report Format | txt, html | html, excel, text, kml, stix, tsk file | html | txt | txt, csv, excel | html |
| 3 | Hash Support | - | O | O | O | O | O |
| 4 | Hash Set | - | O | O | O | O | O |
| 5 | Error Handling Report | O | O | O | - | - | O |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license.
Share and Cite
Kim, S.-H.; Yoon, C. Designing and Validating a Forensic Evaluation Model for Selective Seizure Capabilities in Windows Forensic Tools. Digital 2026, 6, 29. https://doi.org/10.3390/digital6020029
Kim S-H, Yoon C. Designing and Validating a Forensic Evaluation Model for Selective Seizure Capabilities in Windows Forensic Tools. Digital. 2026; 6(2):29. https://doi.org/10.3390/digital6020029
Chicago/Turabian StyleKim, Sun-Ho, and Cheolhee Yoon. 2026. "Designing and Validating a Forensic Evaluation Model for Selective Seizure Capabilities in Windows Forensic Tools" Digital 6, no. 2: 29. https://doi.org/10.3390/digital6020029
APA StyleKim, S.-H., & Yoon, C. (2026). Designing and Validating a Forensic Evaluation Model for Selective Seizure Capabilities in Windows Forensic Tools. Digital, 6(2), 29. https://doi.org/10.3390/digital6020029

