Although the wide use of technology came with many advantages and facilities to the people daily life, it causes the cybercrime to be raised. Digital forensics is one of the most important scientific fields, aiming to investigate cybercrimes and analyze digital evidence. Among different technology’s platforms, operating systems is one of the most important sources of evidence for digital forensic analysts providing a rich information that can used to get important insights. Examples of such evidence include identifying programs that have been executed on a computer, determining files that have been accessed, and identifying storage devices that were connected via USB ports. Practically, accessing and handling this raw information using manual methods is time-consuming, in addition to the lack of accuracy in results due to human errors. In this work, a GUI-based tool is presented to handle most of the evidence provided by Windows operating system that can be used in digital forensics. The research aims to fill the gap caused by the lack of a free tool that deals with these sources, as most available tools are either commercial tools that are complex to use and require expert-level experience. In contrast, available free tools have limited-capability since they are focusing only on one type of evidence. The introduced tool was designed and developed using the C# programming language and was tested on the Windows 10 operating system, where it successfully extracted the required information efficiently and smoothly.
Copyrights © 2026