7-Zip is a free and open-source file archiver program that can compress files, store them in compressed containers called "archives", and can decompress them as well. 7-Zip has its archive format, 7z, with a .7z file extension, but it can also read and write a variety of other formats. 7-Zip was originally developed in 1999 by Igor Pavlov.
Nowadays, most people choose compressed files for sharing and transferring huge volumes of data. As a result, file compression programs can provide critical data to digital investigations that shouldn’t be overlooked, since they act as data containers storing several files and directories in a compressed format.
7-Zip stores its artifacts within the NTUSER.DAT hive at: NTUSER.DAT\Software\7-Zip\
The NTUSER.DAT file is a registry hive file. The registry file format is a binary file like a filesystem with a group of keys, subkeys, and values. These files are used by the operating system to store user, system, and application configurations.
This section discusses how to use ArtiFast Windows to analyze 7-Zip artifacts from Windows
machines and what kind of digital forensics insight we can gain from the artifacts.
After you have created your case and added evidence for the investigation, at the Artifacts Selection phase,
you can select 7-Zip artifacts:
Once ArtiFast parser plugins complete processing artifacts for analysis, it can be reviewed via “Artifact View” or “Timeline View”, with indexing, filtering, and searching capabilities. Below is a detailed description of 7-Zip artifacts in ArtiFast Windows.
7-Zip Archived Files History Artifact
The artifact extracts the list of archived
files using Add to Archive window.
7-Zip Folder History Artifact
The artifact extracts opened archived history.
7-Zip Copy History Artifact
The artifact extracts folder locations where files were
extracted using the Copy button inside 7-zip.
7-Zip Extract History Artifact
The artifact displays folder locations where files
were extracted using 'Extract' inside 7-zip or context menu.
7-Zip Working Folder Option Artifact
The artifact parses working folder options.
7-Zip Default Panels Path Artifact
The artifact shows the last folder the user
checked using 7-zip GUI.
For more information or suggestions please contact: lina.alsoufi@forensafe.com