Thumbnail Cache Viewers¶
What the viewers do¶
Windows thumbnail-cache examination
Thumbs Viewer and Thumbcache Viewer recover cached image previews from two
different Windows database families. Use Thumbs Viewer for folder-level
Thumbs.db and related legacy databases. Use Thumbcache Viewer for per-user
thumbcache_*.db and iconcache_*.db databases from Windows Vista through
Windows 11.
The recovered preview is an investigative lead, not proof that an original file still exists or that a named user deliberately opened it. Preserve the database path, profile or folder context, hashes, exact field labels, and the method used to map any filename or path.
Choose the correct viewer¶
Folder-level and legacy
Thumbs Viewer¶
Extract and preview images from Thumbs.db, ehthumbs.db,
ehthumbs_vista.db, Image.db, Video.db, TVThumb.db, and
musicThumbs.db databases.
Start here when: the database travelled with, or was recovered from, a specific directory.
Per-user and modern
Thumbcache Viewer¶
Extract and preview images and icons from thumbcache_*.db and
iconcache_*.db. It can verify cache-entry checksums and attempt to map entry
hashes using files or Windows Search data.
Start here when: the cache came from a user's Explorer cache profile.
The filename chooses the viewer
Open Thumbs.db and the other listed legacy databases in Thumbs Viewer.
Open thumbcache_*.db or iconcache_*.db in Thumbcache Viewer. A parse
failure is often a source-selection problem, not evidence that the file is
empty.
Choose your journey¶
Download the correct builds, record provenance, and open both supplied interfaces.
Complete when the tools and versions are attributable.Beginner · Windows · 10–20 min 02Analyse and exportSelect the correct viewer, inspect entries, preserve context, and export reviewable results.
Complete when one thumbnail is traceable to its source database.Practical · Working copies · 20–35 min 03Hands-on LabsInvestigate two realistic cache sources in a browser simulation or isolated VM.
Complete when your conclusion states evidence and limitations separately.Guided · 20–90 minEvidence workflow¶
The source database, original path, user or folder context, viewer settings, selected entry metadata, and exported-file hashes form one evidence trail. Keep them together so another analyst can reproduce the observation without relying on the preview image alone.
A verified working copy of the thumbnail database, not the live source.
Source path, user or folder context, database SHA-256, tool/version, entry identifier and export hash.
Windows retained a cached preview consistent with the image; corroboration is required for attribution and activity.
Locate the source in acquired evidence¶
| Database family | Typical context | Collection note |
|---|---|---|
Thumbs.db |
Inside the directory whose items were cached; the file may be hidden | Preserve the database with its directory and volume context. Do not search by filename alone and discard its parent path. |
thumbcache_*.db |
%LocalAppData%\Microsoft\Windows\Explorer for a Windows user profile |
Collect the related cache family and retain the profile SID or identity, original path, and host context. |
iconcache_*.db |
The same per-user Explorer cache area on supported Windows versions | Keep related icon and thumbnail databases together where scope and storage permit. |
| Other databases supported by Thumbs Viewer | Application- or Windows-version-specific locations | Record the exact acquired path and avoid generalising one format's fields to another. |
Absence from an expected path is not proof that thumbnails were never created. The cache may have been disabled, cleaned, rotated, overwritten, excluded from collection, stored elsewhere, or associated with another profile.
What thumbnail evidence can support¶
Supported observation
A selected database contained a recoverable cached image record with the reported identifier, size, metadata, and content at examination time.
Not established alone
The original file still exists; a named user opened it; the cached image is the full original; or a displayed database or entry value is the time of viewing.
Cache context is not user intent
Thumbnail creation can result from Explorer display, application activity, indexing, or other system behaviour. Treat mapping results and recovered names as leads. Corroborate them with file-system metadata, LNK files, Jump Lists, ShellBags, Windows Search, application records, and case context.