🔍
Windows Forensic Handbook
Search...
Ctrl + K
Artifacts by Activity
🏃♂️
Execution
First Executed
Prefetch
AutomaticDestinations Jumplists
Task Scheduler Files
Tracing Registry Keys
Task Scheduler Operational Log
EventID 4104: PowerShell Script Block Logging
Last updated
1 year ago