Windows Search Index and WordWheelQuery
Also called Windows.edb, Windows.db, search index forensics, WordWheelQuery, Explorer search history.
- PLATFORM
- Windows
- CATEGORY
- File and Folder Access
- INDEX
- 8 of 36
- PROVES
- 5 findings
- CANNOT PROVE
- 6 limits
- QUESTIONS
- 3 answered
The desktop search database indexes file properties and, for many file types, full text — so it can retain the content of documents that were deleted before the index was rebuilt.
Where it lives
%ProgramData%\Microsoft\Search\Data\Applications\Windows\ — Windows.edb on Windows 10 and earlier, Windows.db on newer Windows 11 builds; search terms in NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Explorer\WordWheelQuery
Name the location in the preservation request rather than describing the artifact in general terms. A request that asks for the record by its path is one the responding party can act on and one a court can enforce; a request for “all forensic evidence of windows search index and wordwheelquery” is neither.
What it records
The indexer walks configured locations and stores per-item properties — path, name, size, dates, author, and type-specific fields — together with extracted full text for formats it can parse, and it indexes mail items where a mail client participates. It is a cache rather than a log: entries reflect the last time the indexer saw an item, and stale entries for removed items can persist until the index is maintained. The storage format changed between Windows 10 and newer Windows 11 builds, from an ESE database to a set of SQLite databases, so tooling and field availability differ by version.
What it proves — and what it cannot
These two panels carry equal weight, deliberately. The right-hand column is not a disclaimer: it is the specific, mechanical reason an inference fails, and it is the column opposing counsel will read back to a witness on cross-examination.
What it proves
FINDINGS THIS ARTIFACT WILL SUPPORT ON ITS OWN TERMS.
- That a file with a given name, path and properties existed on the system when the indexer last ran
- The text content of documents that have since been deleted, where full-text indexing covered them — one of the few places recoverable content survives without carving
- Author, title and other embedded document properties for files no longer present
- That indexed mail items existed, where the mail client participated in indexing
- From WordWheelQuery, the terms a user typed into the Explorer search box, in most-recent-first order
What it cannot prove
INFERENCES IT WILL NOT CARRY, HOWEVER STRONGLY IT POINTS.
- When a file was accessed or by whom. The index records item properties, not access events, and carries no user attribution for the act of opening anything
- That an indexed item was ever opened. Indexing is automatic and covers files a user never touched
- That an item still existed at any given moment. Entries can outlive the file, so an index hit dates the indexer's visit and not the file's life
- That an unindexed file did not exist. Indexing is scoped to configured locations, excludes many types, and is often disabled on servers and on systems where it was turned off for performance
- From WordWheelQuery, when any term other than the most recent was typed — it is a registry MRU list with one last-write time — or what the user did with the results
- That a search term reflects intent about a specific file. Typing a term shows what was looked for, not what was found or opened
How the finding is attacked
An opinion built on this artifact meets these arguments. Each of them is answerable, and each of them is answered before the report is served rather than at a deposition.
- Establishing that the indexed location list excluded the directories at issue, so the absence of a hit is meaningless
- Arguing that recovered index content is a stale copy that may not match the file as it stood on the date in question
- Pointing to the format change between Windows 10 and 11 and asking whether the tool used was validated against the build examined
- Noting that WordWheelQuery on current builds does not capture Start-menu or system-wide search, so an empty key is not an absence of searching
What survives, and for how long
The index survives reboots and can retain properties and text for files deleted long before, until maintenance removes the stale entries or the index is rebuilt. Rebuilding it — which a user can trigger from the control panel — destroys that history in a single step and leaves a database that looks entirely normal.
More matters are decided by what an artifact never kept than by what it says, which makes preservation timing the most consequential decision in the matter — and it is usually made months before anyone examines anything. The evidence preservation deadline calculator works from the date you first anticipated litigation.
Questions counsel ask
Can the Windows search index recover deleted files?
It can recover their properties and, for formats the indexer parses, their extracted text — not the original file itself. Because the index is a cache rather than a log, entries can outlive the files they describe, so a document deleted before the index was maintained may still be readable in substance. That makes it one of the few sources of deleted content that requires no carving.
Where is the Windows search index stored?
Under %ProgramData%\Microsoft\Search\Data\Applications\Windows. On Windows 10 and earlier it is a single ESE database, Windows.edb. Newer Windows 11 builds moved to a set of SQLite databases named Windows.db and companions. The difference matters practically: parsing tools are version-specific, and a tool validated against one format should not be assumed to read the other correctly.
What is the WordWheelQuery registry key?
It records the search terms a user typed into the Windows Explorer search box, in most-recent-first order, in that user's own registry hive. Only the most recent term can be dated, because the key carries a single last-write time. On current builds it does not capture Start-menu or system-wide search, so an empty key shows nothing about whether the user searched at all.
Terms used on this page
Every term below is defined in the forensic glossary — what it is, why a case turns on it, and what happens when it is mishandled.
Related artifacts
No artifact carries a matter on its own. These are the records that corroborate, contradict, or supply the timeline this one cannot.
RecentDocs and the Open/Save MRU Keys
Per-user registry lists of recently opened documents and of the folders used in Open and Save dialogs, ordered by recency but carrying a timestamp only for the most recent entry.
Spotlight Metadata Store
The macOS metadata index, holding per-file attributes including last-used dates, use counts, and the URL a downloaded file came from — often for files that no longer exist.
$MFT (Master File Table)
The NTFS index of every file and directory on a volume, holding two independent sets of four timestamps per file plus, for small files, the file's entire content.
Recycle Bin ($I and $R Files)
Deleted files moved to the Recycle Bin are stored as a renamed copy of the content plus a metadata file recording the original path, original size and the deletion time.
Whether the windows search index and wordwheelqueryevidence in your matter supports the opinion built on it is a question with a testable answer. Law & Forensics retains court-tested digital forensic expert witnesses and forensic neutrals.
A conflicts check and scoping call follow, normally within one business day. Please do not send privileged or case-sensitive material until conflicts have cleared.
- Can This Artifact Prove That?
Start from the claim rather than the artifact: which records bear on it, and what no combination of them establishes.
- Computer forensics
The examination this artifact is collected and analysed in, scoped to a matter and reported so it can be tested.
- The artifact index
All 36 entries, grouped by what they bear on and filterable by platform.
- Daubert and digital evidence
Why an opinion stated one level too strongly is an admissibility problem rather than a point for cross-examination.
Attorney advertising / expert services. This page describes forensic artifacts and the procedural rules that govern expert evidence in general terms. Artifact behaviour varies by operating-system version, build, and configuration, and every observation has to be verified against the system actually in front of you. Nothing here is legal advice, and it is not a substitute for checking the rules, standing orders, and case law of your own forum.