Authors: Hyunwoo Shin, Jungheum Park
DFRWS APAC 2026
Abstract
Windows forensic investigations rely on heterogeneous artifacts such as Event Logs, Prefetch, Amcache, browser records, and file system metadata to reconstruct user and system activities. However, selective deletion, clearing, or regeneration can undermine conclusions drawn from a single source. CAFE addresses this problem by linking examiner-supplied candidate claims to normalized evidence items and explicitly representing provenance, support, conflict, and explained absence across artifact families. It separates the reconstruction of event claims from identifying which artifact family has become less reliable due to manipulation, allowing the loss of evidence supporting a claim and the degradation of that artifact family’s continuity to be reported as distinct outcomes. We evaluate CAFE on Windows 10 and Windows 11 using seven controlled scenarios with three repetitions per operating system. CAFE raised no high severity conflicts in clean runs and localized all declared target surfaces in 34 of 36 manipulated runs. When manipulation removed a claim’s primary source, reduced claim support exposed the resulting evidentiary loss rather than inferring an unsupported event. These findings demonstrate the feasibility of claim level cross artifact analysis as an explainable verification layer under controlled conditions.