Windows 10 Mail App Forensics

May 27 · 6 min read
Directory Listings for the Windows 10 Mail App Artefacts
XWays displaying calendar invitations
OSForensics parsing .dat files in \data\33

Using OS Forensics to Extract store.vol
OSForensics String Viewer to search store.vol for email data
Using OSForensic’s ESEDB Viewer to parse store.vol

Attempting to use NirSoft’s ESEDatabaseView to parse store.vol
Attempting to use Autopsy to parse store.vol


Written by

Your one and only source into the scandalous life of a DFIR consultant.

Welcome to a place where words matter. On Medium, smart voices and original ideas take center stage - with no ads in sight. Watch
Follow all the topics you care about, and we’ll deliver the best stories for you to your homepage and inbox. Explore
Get unlimited access to the best stories on Medium — and support writers while you’re at it. Just $5/month. Upgrade