🔍
Windows Forensic Handbook
More
Search
Ctrl + K
Evidence of Execution
Last updated
1 year ago
Prefetch
Amcache.hve
System Resource Usage Monitor (SRUM)
Background Activity Montitor
AutomaticDestinations Jumplists
Task Scheduler Files
Task Scheduler Operational Log
Windows Error Reporting Files (.WER)
Tracing Registry Keys
EventID 4688: A new process has been created
EventID 2004: Firewall Rule Added
EventID 2005: Firewall Rule Modified
EventID 2006: Firewall Rule Deleted
EventID 2071: Firewall Rule Added
EventID 2073: Firewall Rule Modified
EventID 2052: Firewall Rule Deleted
EventID 9707: Command Execution Started
EventID 4104: PowerShell Script Block Logging