# Artifacts by Activity

- [Execution](https://psmths.gitbook.io/windows-forensics/artifacts-by-activity/execution.md): Execution artifacts provide evidence of programs and applications being run on a system.
- [Evidence of Execution](https://psmths.gitbook.io/windows-forensics/artifacts-by-activity/execution/evidence-of-execution.md)
- [First Executed](https://psmths.gitbook.io/windows-forensics/artifacts-by-activity/execution/first-executed.md)
- [Last Executed](https://psmths.gitbook.io/windows-forensics/artifacts-by-activity/execution/last-executed.md)
- [Command Line Options](https://psmths.gitbook.io/windows-forensics/artifacts-by-activity/execution/command-line-options.md)
- [Execution Account](https://psmths.gitbook.io/windows-forensics/artifacts-by-activity/execution/execution-account.md)
- [Parent and Child Information](https://psmths.gitbook.io/windows-forensics/artifacts-by-activity/execution/parent-and-child-information.md)
- [Execution Timestamp](https://psmths.gitbook.io/windows-forensics/artifacts-by-activity/execution/execution-timestamp.md)
- [File Activity](https://psmths.gitbook.io/windows-forensics/artifacts-by-activity/file-activity.md): File Activity artifacts are generated by filesystem actions such as creating, modifying, or deleting files.
- [File Creation](https://psmths.gitbook.io/windows-forensics/artifacts-by-activity/file-activity/creation.md)
- [File Deletion](https://psmths.gitbook.io/windows-forensics/artifacts-by-activity/file-activity/deletion.md)
- [Last Modified](https://psmths.gitbook.io/windows-forensics/artifacts-by-activity/file-activity/last-modified.md)
- [File Origin](https://psmths.gitbook.io/windows-forensics/artifacts-by-activity/file-activity/origin.md)
- [File Size](https://psmths.gitbook.io/windows-forensics/artifacts-by-activity/file-activity/size.md)
- [File Path](https://psmths.gitbook.io/windows-forensics/artifacts-by-activity/file-activity/file-path.md)
- [File Hash](https://psmths.gitbook.io/windows-forensics/artifacts-by-activity/file-activity/file-hash.md)
- [Account Activity](https://psmths.gitbook.io/windows-forensics/artifacts-by-activity/account-activity.md): In certain circumstances, some artifacts may provide information about an account, or attribution of certain activity to a particular account.
- [Account Creation Time](https://psmths.gitbook.io/windows-forensics/artifacts-by-activity/account-activity/creation-time.md)
- [Group Membership](https://psmths.gitbook.io/windows-forensics/artifacts-by-activity/account-activity/group-membership.md)
- [Last Login](https://psmths.gitbook.io/windows-forensics/artifacts-by-activity/account-activity/last-login.md)
- [Login History](https://psmths.gitbook.io/windows-forensics/artifacts-by-activity/account-activity/login-history.md)
- [Logon ID](https://psmths.gitbook.io/windows-forensics/artifacts-by-activity/account-activity/logon-id.md)
- [Relative Identifier](https://psmths.gitbook.io/windows-forensics/artifacts-by-activity/account-activity/relative-identifier.md)
- [Security Identifier](https://psmths.gitbook.io/windows-forensics/artifacts-by-activity/account-activity/security-identifier.md)
- [Username](https://psmths.gitbook.io/windows-forensics/artifacts-by-activity/account-activity/username.md)
- [Network Activity](https://psmths.gitbook.io/windows-forensics/artifacts-by-activity/network-activity.md): Network activity can be analyzed through certain artifacts, which may provide information such as the source or destination of certain network traffic, or the volume of that activity.
- [Evidence of Network Activity](https://psmths.gitbook.io/windows-forensics/artifacts-by-activity/network-activity/evidence-of-network-activity.md)
- [Destination Identification](https://psmths.gitbook.io/windows-forensics/artifacts-by-activity/network-activity/destination-identification.md)
- [Source Identification](https://psmths.gitbook.io/windows-forensics/artifacts-by-activity/network-activity/source-identification.md)
- [Transmit Volume](https://psmths.gitbook.io/windows-forensics/artifacts-by-activity/network-activity/transmit-volume.md)
- [Firewall Activity](https://psmths.gitbook.io/windows-forensics/artifacts-by-activity/network-activity/firewall-activity.md)
- [Wireless Activity](https://psmths.gitbook.io/windows-forensics/artifacts-by-activity/network-activity/wireless-activity.md)
- [Browser Activity](https://psmths.gitbook.io/windows-forensics/artifacts-by-activity/browser-activity.md)
- [History](https://psmths.gitbook.io/windows-forensics/artifacts-by-activity/browser-activity/history.md)
- [Firefox places.sqlite Database](https://psmths.gitbook.io/windows-forensics/artifacts-by-activity/browser-activity/history/firefox-places-sqlite.md)
- [Bookmarks](https://psmths.gitbook.io/windows-forensics/artifacts-by-activity/browser-activity/bookmarks.md)
- [Stored Passwords/Secrets](https://psmths.gitbook.io/windows-forensics/artifacts-by-activity/browser-activity/stored-passwords-secrets.md)
- [System Enumeration](https://psmths.gitbook.io/windows-forensics/artifacts-by-activity/system-enumeration.md)


---

# Agent Instructions: Querying This Documentation

If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter:

```
GET https://psmths.gitbook.io/windows-forensics/artifacts-by-activity.md?ask=<question>
```

The question should be specific, self-contained, and written in natural language.
The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
