# Private Web Browser Forensics: A Case Study on Epic Privacy Browser

Canonical URL: https://markscanlon.co/publications/PrivateWebBrowserForensics

CSL-JSON: https://markscanlon.co/publications/PrivateWebBrowserForensics.csl.json
BibTeX: https://markscanlon.co/publications/PrivateWebBrowserForensics.bib
RIS: https://markscanlon.co/publications/PrivateWebBrowserForensics.ris

Authors: Alan Reed; Mark Scanlon; Nhien-An Le-Khac
Venue: Journal of Information Warfare
Year: 2018
PDF: https://markscanlon.co/publications/PrivateWebBrowserForensics.pdf
Full text: https://markscanlon.co/publications/PrivateWebBrowserForensics.full.md

## Contribution Summary

This research paper presents a case study on the Epic Privacy Browser, a private web browser designed to protect users' privacy. The study aims to investigate the types of evidence left behind by the browser on Windows 10 and Windows 7 operating systems, including live and post-mortem analysis. The researchers used various forensic tools to analyze the browser's artefacts, including Process Monitor, Regshot, and FTK Imager. The study identifies the types of evidence that can be recovered from the browser, including cache, temporary files, and cookies. The researchers also examine the effectiveness of the browser's claim that all traces of user activity are cleared upon closure. The study's findings have implications for forensic investigators and researchers interested in preserving privacy and triage processes.

## Abstract

Organized crime, as well as individual criminals, are benefiting from the protection of private browsers to carry out illegal activity, such as money laundering, drug trafficking, the online exchange of child abuse material, etc. Epic Privacy Browser is one common example. It is currently in use in approximately 180 countries worldwide. In this paper, we outline the location and type of evidence available through live and post-mortem state analysis of the Epic Privacy Browser. This analysis identifies how the browser functions during use and where evidence can be recovered after use, the tools, and effective presentation of the recovered material.

