[Paper Review] Forensic Analysis of Epic Privacy Browser on Windows Operating Systems
This paper presents a forensic analysis of Epic Privacy Browser on Windows systems, identifying and documenting digital artifacts across various storage locations such as the Windows Registry, browser profiles, and temporary directories. The study reveals that despite its privacy-focused design, Epic leaves significant forensic traces, including cached data, browsing history, and configuration files, which can be recovered and analyzed by digital investigators.
The 16th European Conference on Cyber Warfare and Digital Security (ECCWS 2017), Dublin, Ireland, 29-30 June 2017
Motivation & Objective
- To investigate the digital forensic footprint of Epic Privacy Browser on Windows operating systems.
- To identify and document persistent data remnants left by the browser after user activity.
- To evaluate the effectiveness of Epic's privacy features in preventing forensic data leakage.
- To provide digital investigators with a comprehensive guide to extracting and analyzing forensic evidence from Epic Privacy Browser.
Proposed method
- Conducted a systematic examination of Windows system artifacts, including the Registry, AppData directories, and temporary files, to locate Epic browser data.
- Performed controlled browsing sessions using Epic Privacy Browser on Windows 10 and Windows 7 systems.
- Collected and analyzed forensic artifacts such as cache files, cookies, browsing history, and configuration files.
- Used digital forensics tools (e.g., Autopsy, SIFT) to extract and examine data from disk images.
- Mapped the persistence and recoverability of data across different browser settings and cleanup operations.
- Classified data types based on their sensitivity and forensic relevance.
Experimental results
Research questions
- RQ1What types of digital artifacts does Epic Privacy Browser leave behind on Windows systems?
- RQ2How persistent are these artifacts after standard browsing and cleanup procedures?
- RQ3To what extent do Epic's privacy features prevent the creation or retention of forensic evidence?
- RQ4Which storage locations contain the most forensically valuable data from Epic?
Key findings
- Epic Privacy Browser leaves behind recoverable browsing history in the form of indexed database files, even after clearing history.
- Cache files, including thumbnails and web content, were found in the AppData\Local\Epic\User Data\Default\Cache directory.
- Configuration settings and user preferences were stored in JSON-formatted files within the User Data directory, accessible post-browsing.
- The Windows Registry contained entries related to browser installation and user profile settings, which could be used to reconstruct user activity.
- Temporary files and web cache data persisted in the Temp directory, even after browser closure.
- Despite its privacy-focused design, Epic does not fully erase forensic traces, enabling digital investigators to reconstruct user behavior.
Better researchstarts right now
From reading papers to final review, dramatically reduce your research time.
No credit card · Free plan available
This review was created by AI and reviewed by human editors.