Microsoft Forensics
Looking for:
Forensic Artifact
Forensics locations:
Object
Location
Main forensics artifacts:
CyLR config file:
Last updated
Last updated
# Post 2008 R2
C:\Windows\System32\winevt\logsC:\windows\tasks
C:\windows\System32\Tasks
C:\windows\sysWOW64\Tasks# User files
C:\Users\[username]\AppData\Roaming\Microsoft\Windows\Recent\
C:\Users[username]\AppData\Local\Microsoft\Windows\FileHistory\Data
# Office Files:
C:\Users\AppData\Roaming\Microsoft\Office\Recent\
# Recent File cache
%systemroot%\AppCompat\Programs\RecentFileCache.bcfC:\Users\*\AppData\Local\Microsoft\Windows\INetCookies
C:\Users\*\AppData\Roaming\Microsoft\Windows\Cookies
C:\Users\*\AppData\Roaming\Microsoft\Windows\Cookies\Low%SystemDrive%/hiberfil.sys
# Can be used to get memory of a powered off image%SystemDrive%/pagefile.sys
# Can be used to get memory of a powered off image%WinDir%/MEMORY.DMPC:\Windows\PrefectchC:\Users\<USERNAME>\NTUSER.DAT
C:\Users\<USERNAME>\NTUSER.DAT.LOG1
C:\Users\<USERNAME>\NTUSER.DAT.LOG2
C:\Users\<USERNAME>\AppData\Local\Microsoft\Windows\UsrClass.dat
C:\Users\<USERNAME>\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG1
C:\Users\<USERNAME>\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG2C:\Windows\AppCompay\Programs\Amcache.hveC:\Windows\System32\config\SAM
C:\Windows\System32\config\SYSTEM
C:\Windows\System32\config\SECURITY
C:\Windows\System32\config\SOFTWARE
C:\Windows\System32\config\SAM.LOG1
C:\Windows\System32\config\SAM.LOG2
C:\Windows\System32\config\SYSTEM.LOG1
C:\Windows\System32\config\SYSTEM.LOG2
C:\Windows\System32\config\SECURITY.LOG1
C:\Windows\System32\config\SECURITY.LOG2
C:\Windows\System32\config\SOFTWARE.LOG1
C:\Windows\System32\config\SOFTWARE.LOG2C:\$MFT
C:\$J
C:\$Logs
C:\$Recycle.Bin
C:\$LogFile
C:\Windows\Tasks
C:\Windows\Prefectch
C:\Windows\inf\setupapi.dev.log
C:\Windows\Appcompat\Programs
C:\Windows\System32\sru
C:\Windows\System32\winevt\logs
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\
C:\Users\<USERNAME>\AppData\Roaming\Microsoft\Windows\Recent
C:\Users\<USERNAME>\AppData\Local\Microsoft\Windows\Explorer