
16.08.2026 windows recallendpoint forensicsai artifactsinsider threat
Since Microsoft rolled out Recall on Copilot+ PCs, the evidentiary landscape on Windows systems has changed fundamentally. The feature was first introduced in May 2024 and allows the computer to remember everything a user has done over the past few months by taking screenshots of the entire display every few seconds, which a local AI engine then analyzes and saves to a database. For incident responders, this means that where Prefetch entries, Amcache records, or browser history once offered only indirect clues about user activity, Recall now delivers literal visual proof of what was on screen.
The relevant data structures live in a well-defined per-user path. Recall data is saved per-user in the user’s profile directory, with the relevant artifacts being the “ImageStore” directory storing screenshots in JPEG format, “ukg.db” a SQLite database containing URLs and OCR’d text, and the SemanticTextStore/SemanticImageStore DiskANN graph databases. Particularly rich is the EXIF MakerNote tag attached to every capture: this tag holds a significant amount of interesting data, such as the boundaries of the foreground window, the capture timestamp, the window title, the window identifier, and the full path of the process that launched the window – and if a browser was in use, even the URI and domain.
For investigators, this is a springboard to complete activity reconstruction. A recent open-source project called RecallTimeline addresses exactly this gap: it is a Python open-source tool for forensic recovery of Windows Recall artifacts, whose automated anomaly detection engine uses 29 keyword-based rules to detect confidential file access, cloud uploads, LOLBin launches, and burst patterns. In one tested insider-threat case, the tool decoded 65 events across 37 days, detected 34 anomalies, and completed the analysis in under five seconds — roughly 180 times faster than manual ExifTool-based processing.
Tempting as this wealth of data is, current research urges caution before relying on it in court. A May 2026 study tested five hypotheses concerning application name accuracy, timestamp reliability, screenshot fidelity, OCR accuracy, and the capture of contextual UI elements, noting that while public attention has focused on Recall’s security implications, little research has addressed its significance for digital forensics. Its sobering conclusion: Recall’s memory, it turns out, is not always “photographic”. In practice, this means every Recall-derived timeline must be cross-validated against independent artifacts — SRUM, firewall logs, process execution traces — before it can serve as courtroom-ready evidence.
At the same time, the attack surface keeps growing. Recall activation is granular and registry-controlled: it is activated on a per-user basis via a key in the user’s registry hive, specifically Software\Policies\Microsoft\Windows\WindowsAI — a mechanism that doubles as an anti-forensic lever, since disabling capture or selectively deleting snapshots leaves a deliberate gap in the evidence chain. Meanwhile, infostealer operators are increasingly focused on harvesting local databases containing sensitive user data, a pattern that maps directly onto ukg.db once attackers recognize the treasure trove it represents.
As Recall expands into enterprise environments via Microsoft Intune, it graduates from consumer gimmick to a serious enterprise artifact. IR teams should add Recall snapshots to their standard collection checklists — while clearly communicating the AI engine’s error rate in any report. Ignore Recall, and you leave evidence on the table; trust it blindly, and you risk building a case on shaky ground.
← Back to overview