TypedURLs is a Windows Registry key that is similar in concept to TypedPaths key. The key records
URLs typed or inserted in the Internet Explorer (IE) address bar. URLs that are completed by the browser’s
AutoComplete functionality are not recorded in the key unless the website was previously visited by the
user. The key is also updated when the user selects a URL from the list of stored URLs via the address bar
drop-down menu. However, URLs that are accessed via Internet Explorer Favorites menu or the user’s home page
will not be recorded. In addition, if the user cleared IE’s browsing history, the TypedURLs key and all of the values
within will be deleted from the registry.
It is important to note that the key is populated by default even prior to opening Internet Explorer. The
value seen in the figure below is not typed or inserted by the user. This entry is populated by default and
it stores the webpage which will be requested to the user upon launching the browser for the first time.
Lastly, the key is populated differently depending on the versions of both Internet Explorer and Windows.
For instance, in IE6, the TypedURLs key is only populated when the browser is closed properly. On the other
hand, in IE8 and later versions, the key is updated and populated in real time.
Windows Registry is considered an important source for potential evidential data as it contains a wealth of information related to the user activity on the system. Typed URLs key may reveal the websites that the suspect has recently accessed via Internet Explorer.
TypedURLs key is located at: NTUSER.DAT\Software\Microsoft\Internet Explorer\TypedURLs
Similar to TypedPaths subkey, the values within TypedURLs key are assigned names such as “url1”, “url2”,
“url3” and
so on. The first value added is named “url1”, however, when a new value is added, the previous value will be
named “url2” and the new value will be named “url1”. Therefore, the names of the values keep changing but
the value named “url1” will always hold the most recent visited URL.
This section discusses how to use ArtiFast Windows to analyze Typed URLs artifact from Windows machines and
what kind of digital forensics insight we can gain from the artifact.
After you have created your case and added evidence for the investigation, at the Artifacts Selection phase,
you can select Typed URLs Artifact:
Once ArtiFast parser plugins complete processing artifacts for analysis, it can be reviewed via “Artifact View” or “Timeline View”, with indexing, filtering, and searching capabilities. Below is a detailed description of Typed URLs artifact in ArtiFast Windows.
Typed URLs Artifact
This artifact contains the full URLs typed or inserted in the
Internet Explorer (IE) address bar. The details you can view include:
For more information or suggestions please contact: asmaa.elkhatib@forensafe.com