Desktop search applications have improved dramatically over the last three years, evolving from time-consuming search applications
to instantaneous search tools that rely extensively on pre-cached data. This paper investigates the extraction of pre-cached
data for forensic purposes, drawing on earlier work to automate the process. The result is a proof-of-concept application
called Google Desktop Search Evidence Collector (GDSEC), which interfaces with Google Desktop Search to convert data from
Google’s proprietary format to one that is amenable to offline analysis.
Keywords Google Desktop Search - evidence extraction