diff --git a/scripts/artifacts/chromiumSessions.py b/scripts/artifacts/chromiumSessions.py index 4b4eb0a6..d664526f 100644 --- a/scripts/artifacts/chromiumSessions.py +++ b/scripts/artifacts/chromiumSessions.py @@ -25,8 +25,12 @@ "current releases, and Current Session and Last Session in the profile folder of older " "ones, as in lonewolf_win10's Chrome profile; Sessions_Encrypted/Session_ is " "matched too. Browser, Profile and User come from the path: the browser from the user " - "data folder, the profile from the folder inside it, and the user from the home folder " - "that holds it; Source File names the file each row came from. Browser, Profile and User " + "data folder, the profile from the folder inside it, and the user from the home " + "folder that holds it; Source File names the file each row came from. Window ID " + "is read from each record, and Window ID, Browser, Profile and User do not " + "separate the session files of one profile, as lonewolf_win10's profile holds " + "both a Current Session and a Last Session, so " + "Source File is what names the file. Browser, Profile and User " "each held one value on every row of lonewolf_win10, which carries one Chrome profile in " "one home folder, and User held one value on every row of pc_mus_001_win11, whose Chrome " "and Edge profiles sit in one home folder. Only the Windows Google Chrome and Microsoft " diff --git a/scripts/artifacts/macosTCC.py b/scripts/artifacts/macosTCC.py index ae22dd25..81d59175 100644 --- a/scripts/artifacts/macosTCC.py +++ b/scripts/artifacts/macosTCC.py @@ -22,9 +22,11 @@ "requirements": "none", "category": "App Permissions (macOS)", "notes": "Every TCC.db found is parsed (the system store under " - "/Library/Application Support/com.apple.TCC/ and each user's " - "under ~/Library/Application Support/com.apple.TCC/), tagged by " - "Source File. Service is shown without its kTCCService prefix. " + "/Library/Application Support/com.apple.TCC/ and each user's under " + "~/Library/Application Support/com.apple.TCC/), tagged by Source File. No other " + "column names the store: Access and the rest are read from each row, so they do " + "not separate the system store from a user's, and Source File names the store " + "each row came from. Service is shown without its kTCCService prefix. " "Client Type is decoded (0 Bundle ID, 1 Absolute path) and the " "Client is a bundle identifier or an on-disk path accordingly. " "Access is decoded from auth_value on modern schemas (0 Not " diff --git a/scripts/artifacts/windowsJumpLists.py b/scripts/artifacts/windowsJumpLists.py index 15a086b0..0f1461bb 100644 --- a/scripts/artifacts/windowsJumpLists.py +++ b/scripts/artifacts/windowsJumpLists.py @@ -50,9 +50,11 @@ "notes": "Rows from the shell links inside a user's jump list files, read " "from the files named in Source File. Each row is one destination " "shell link. List Type is Automatic for an .automaticDestinations-ms " - "file and Custom for a .customDestinations-ms file. App ID is the " - "jump list file name, an application identifier, as stored; it is not " - "resolved to an application name here. An automatic jump list is an " + "file and Custom for a .customDestinations-ms file. App ID is the jump list file " + "name, an application identifier, as stored; it is not resolved to an application" + " name here. App ID does not separate two users' jump lists for one application, " + "and no column here names the user, so Source File names the file each row came " + "from. An automatic jump list is an " "OLE compound file whose numbered streams are each a shell link, " "ordered here by its DestList stream. MRU Position is the entry's " "place in the DestList's stored order, 1 first; on the tested images " diff --git a/scripts/artifacts/windowsPrefetch.py b/scripts/artifacts/windowsPrefetch.py index 449e0c75..b1e90985 100644 --- a/scripts/artifacts/windowsPrefetch.py +++ b/scripts/artifacts/windowsPrefetch.py @@ -81,7 +81,11 @@ "with many loaded files produces many rows. Executable is the name " "from the prefetch header and Loaded File is the referenced path as " "stored, usually in \\VOLUME{...}\\ form naming the volume by its " - "GUID and serial. Prefetch File is the .pf file name. The list is " + "GUID and serial. " + "Prefetch File is the .pf file name. Prefetch File does not separate two copies " + "of one prefetch file, and the declared path also matches a Prefetch folder under" + " Windows.old, so Source File names the file each row came from." + " The list is " "what the program referenced when it was prepared to run, which " "includes its own image, its DLLs and data files it opened. A " "prefetch file records that Windows prepared an executable to run. " diff --git a/scripts/artifacts/windowsThumbcache.py b/scripts/artifacts/windowsThumbcache.py index 1e3f3b03..650376bd 100644 --- a/scripts/artifacts/windowsThumbcache.py +++ b/scripts/artifacts/windowsThumbcache.py @@ -56,9 +56,11 @@ "not surfaced. Thumbnail is the cached image extracted from the " "entry and shown inline; the entry data is sniffed and only a real " "image (PNG, JPEG, BMP or GIF) is shown, with its format in Data " - "Format and byte count in Data Size. Cache Size is the thumbnail " - "size the file name encodes (for example 256 from thumbcache_256.db, " - "or sr, wide, exif, idx as stored). Cache Entry ID is the entry's " + "Format and byte count in Data Size. Cache Size is the thumbnail size the file " + "name encodes (for example 256 from thumbcache_256.db, or sr, wide, exif, idx as " + "stored). Cache Size does not separate two users' files of one size, and no " + "column here names the user, so Source File names the file each row came from. " + "Cache Entry ID is the entry's " "64-bit ThumbnailCacheId as hex. Identifier is the entry's own " "identifier string as stored, which is sometimes a file path, a " "shell folder GUID or the entry id, and is not a reliable file name. "