Forensics Flashcards
Program Execution Artifacts (7)
UserAssist, Shimcache, Windows 10 Timeline, RecentApps, Jump Lists, System Resource Usage Monitor, Prefetch
Deleted File/File Knowledge Artifacts (4)
Thumbscache, IE/Edge file, Word Wheel Query, Recycle Bin
Network Activity Artifacts (4)
Cookies, Network History, Browser Search Terms, System Resource Usage Monitor
File/Folder Opening Artifacts (6)
Recent Files, Shell Bags, LNK Files, IE/Edge file, Jump Lists, Prefetch
Account Usage Artifacts (2)
Event Logs, RDP Usage
External Device/USB Artifacts (2)
Volume Serial Number, Shortcut (LNK) Files
Browser Usage Artifacts (5)
History, Cookies, Flash and Super Cookies, Session Restore, Google Analytics Cookies
File Download Artifacts (4)
Email Attachments, Browser Artifacts, Downloads, ADS Zone.Identifier
UserAssist
Tracks GUI based programs launched from Desktop
Windows 10 Timeline
Tracks recently used applications and files. Accessible via Win+tab.
Recent Apps
Tracks GUI Program execution launched on Win10.
Shimcache
Tracks Windows application compatability
System Resource Usage Manager
Records histroical system performance. Applications run + user account, bytes sent per application per hour
Prefetch
Increases performance of a system by pre-loading code of commonly used applications.
C:\Windows\Prefetch
Thumbscache
Database of thumbnails of pictures, documents, folders, etc