Evidence Type | Description | UFDR | VFS |
Autofill | Autofill data | ✓ | ✓ |
Bookmarked URLs | URLs bookmarked by users | ✓ | ✓ |
Call Logs | Regular phone calls and VOIP phone calls metadata | ✓ | ✓ |
Chat Messages | Instant chat messages | ✓ | ✓ |
Contacts | Contact of friends and parties | ✓ | |
Cookies | HTTP cookies data | ✓ | ✓ |
Crypto Wallets | Crypto Wallets addresses | ✓ | |
Encryption Keys | Encryption keys used to protect data | ✓ | ✓ |
Installed Programs | Programs installed on Operating System | ✓ | ✓ |
Instant Messages | SMS/MMS and other instant messages | ✓ | |
IP Addresses | External IP addresses recorded by applications | ✓ | ✓ |
Local Files | Files that are/were in suspect disk, according to applications records | | ✓ |
Opened Files | Files opened by users | | ✓ |
Password Hashes | Password hashes, such as NTLM and LM | | ✓ |
Passwords | User passwords | ✓ | ✓ |
Received Files | Files received by users, including donwloaded files and message attachments | ✓ | ✓ |
Searched Texts | Texts searched by users | ✓ | ✓ |
Sent Files | Files sent by users, including donwloaded files and message attachments | ✓ | ✓ |
Shared Files | Files shared by local users | | ✓ |
Trash Can Entries | Operating System's trash can entries | | ✓ |
User Accounts | User accounts | ✓ | ✓ |
Visited URLs | URLs visited by users using browser applications | ✓ | ✓ |
Wireless Connections | Wireless connections, with date/time information | ✓ | ✓ |
Wireless Networks | Wireless networks that were connected, including password information | ✓ | ✓ |