🔍
Windows Forensic Handbook
Ctrlk
  • 👋Welcome
  • Artifacts by Type
    • 🗄️Registry Artifacts
    • 📂Filesystem Artifacts
    • 📅Event Log Artifacts
  • Artifacts by Activity
    • 🏃‍♂️Execution
    • 🗒️File Activity
      • File Creation
      • File Deletion
      • Last Modified
      • File Origin
      • File Size
      • File Path
        • USN Journal
        • Prefetch
        • Amcache.hve
        • Background Activity Montitor
        • System Resource Usage Monitor (SRUM)
        • AutomaticDestinations Jumplists
        • Recycle Bin $I/$R Files
        • Image File Execution Options Registry Keys
        • Task Scheduler Files
        • Windows Error Reporting Files (.WER)
        • Run/RunOnce Registry Keys
        • Services Registry Keys
        • Task Scheduler Operational Log
        • Event ID 7045: Service Installed
        • EventID 2004: Firewall Rule Added
        • EventID 2005: Firewall Rule Modified
        • EventID 2006: Firewall Rule Deleted
        • EventID 2071: Firewall Rule Added
        • EventID 2073: Firewall Rule Modified
        • EventID 2052: Firewall Rule Deleted
      • File Hash
    • 👨‍🔧Account Activity
    • 🌎Network Activity
    • 🔍Browser Activity
    • 🖥️System Enumeration
Powered by GitBook
On this page
  1. Artifacts by Activity
  2. 🗒️File Activity

File Path

USN JournalPrefetchAmcache.hveBackground Activity MontitorSystem Resource Usage Monitor (SRUM)AutomaticDestinations JumplistsRecycle Bin $I/$R FilesImage File Execution Options Registry KeysTask Scheduler FilesWindows Error Reporting Files (.WER)Run/RunOnce Registry KeysServices Registry KeysTask Scheduler Operational LogEvent ID 7045: Service InstalledEventID 2004: Firewall Rule AddedEventID 2005: Firewall Rule ModifiedEventID 2006: Firewall Rule DeletedEventID 2071: Firewall Rule AddedEventID 2073: Firewall Rule ModifiedEventID 2052: Firewall Rule Deleted

Last updated 1 year ago