I am a digital forensics student conducting a research project on the Windows artifacts left behind by using QuickTime Player. I'm using the Windows 7 OS in Bootcamp. I have located the xml document listing the MRU/URL strings but in order to get timestamps/dates of these files I need to carve them in Winhex. Does anyone know what the header/footer is for this? Any input on this or anything else related to my research to help direct me would be greatly appreciated.
Thank you.
↧