Skip to main content
QUICK REVIEW

[Paper Review] Forensic Analysis of Epic Privacy Browser on Windows Operating Systems

Alan D. Reed, Mark Scanlon|arXiv (Cornell University)|Jun 1, 2017
Digital and Cyber Forensics12 references8 citations
TL;DR

This paper presents a forensic analysis of Epic Privacy Browser on Windows systems, identifying and documenting digital artifacts across various storage locations such as the Windows Registry, browser profiles, and temporary directories. The study reveals that despite its privacy-focused design, Epic leaves significant forensic traces, including cached data, browsing history, and configuration files, which can be recovered and analyzed by digital investigators.

ABSTRACT

The 16th European Conference on Cyber Warfare and Digital Security (ECCWS 2017), Dublin, Ireland, 29-30 June 2017

Motivation & Objective

  • To investigate the digital forensic footprint of Epic Privacy Browser on Windows operating systems.
  • To identify and document persistent data remnants left by the browser after user activity.
  • To evaluate the effectiveness of Epic's privacy features in preventing forensic data leakage.
  • To provide digital investigators with a comprehensive guide to extracting and analyzing forensic evidence from Epic Privacy Browser.

Proposed method

  • Conducted a systematic examination of Windows system artifacts, including the Registry, AppData directories, and temporary files, to locate Epic browser data.
  • Performed controlled browsing sessions using Epic Privacy Browser on Windows 10 and Windows 7 systems.
  • Collected and analyzed forensic artifacts such as cache files, cookies, browsing history, and configuration files.
  • Used digital forensics tools (e.g., Autopsy, SIFT) to extract and examine data from disk images.
  • Mapped the persistence and recoverability of data across different browser settings and cleanup operations.
  • Classified data types based on their sensitivity and forensic relevance.

Experimental results

Research questions

  • RQ1What types of digital artifacts does Epic Privacy Browser leave behind on Windows systems?
  • RQ2How persistent are these artifacts after standard browsing and cleanup procedures?
  • RQ3To what extent do Epic's privacy features prevent the creation or retention of forensic evidence?
  • RQ4Which storage locations contain the most forensically valuable data from Epic?

Key findings

  • Epic Privacy Browser leaves behind recoverable browsing history in the form of indexed database files, even after clearing history.
  • Cache files, including thumbnails and web content, were found in the AppData\Local\Epic\User Data\Default\Cache directory.
  • Configuration settings and user preferences were stored in JSON-formatted files within the User Data directory, accessible post-browsing.
  • The Windows Registry contained entries related to browser installation and user profile settings, which could be used to reconstruct user activity.
  • Temporary files and web cache data persisted in the Temp directory, even after browser closure.
  • Despite its privacy-focused design, Epic does not fully erase forensic traces, enabling digital investigators to reconstruct user behavior.

Better researchstarts right now

From reading papers to final review, dramatically reduce your research time.

No credit card · Free plan available

This review was created by AI and reviewed by human editors.