πŸ”
Windows Forensic Handbook
search
⌘Ctrlk
πŸ”
Windows Forensic Handbook
  • πŸ‘‹Welcome
  • Artifacts by Type
    • πŸ—„οΈRegistry Artifacts
    • πŸ“‚Filesystem Artifacts
    • πŸ“…Event Log Artifacts
  • Artifacts by Activity
    • πŸƒβ€β™‚οΈExecution
    • πŸ—’οΈFile Activity
      • File Creation
      • File Deletion
      • Last Modified
      • File Origin
      • File Size
      • File Path
        • USN Journal
        • Prefetch
        • Amcache.hve
        • Background Activity Montitor
        • System Resource Usage Monitor (SRUM)
        • AutomaticDestinations Jumplists
        • Recycle Bin $I/$R Files
        • Image File Execution Options Registry Keys
        • Task Scheduler Files
        • Windows Error Reporting Files (.WER)
        • Run/RunOnce Registry Keys
        • Services Registry Keys
        • Task Scheduler Operational Log
        • Event ID 7045: Service Installed
        • EventID 2004: Firewall Rule Added
        • EventID 2005: Firewall Rule Modified
        • EventID 2006: Firewall Rule Deleted
        • EventID 2071: Firewall Rule Added
        • EventID 2073: Firewall Rule Modified
        • EventID 2052: Firewall Rule Deleted
      • File Hash
    • πŸ‘¨β€πŸ”§Account Activity
    • 🌎Network Activity
    • πŸ”Browser Activity
    • πŸ–₯️System Enumeration
gitbookPowered by GitBook
block-quoteOn this pagechevron-down
  1. Artifacts by Activitychevron-right
  2. πŸ—’οΈFile Activity

File Path

USN Journalchevron-rightPrefetchchevron-rightAmcache.hvechevron-rightBackground Activity Montitorchevron-rightSystem Resource Usage Monitor (SRUM)chevron-rightAutomaticDestinations Jumplistschevron-rightRecycle Bin $I/$R Fileschevron-rightImage File Execution Options Registry Keyschevron-rightTask Scheduler Fileschevron-rightWindows Error Reporting Files (.WER)chevron-rightRun/RunOnce Registry Keyschevron-rightServices Registry Keyschevron-rightTask Scheduler Operational Logchevron-rightEvent ID 7045: Service Installedchevron-rightEventID 2004: Firewall Rule Addedchevron-rightEventID 2005: Firewall Rule Modifiedchevron-rightEventID 2006: Firewall Rule Deletedchevron-rightEventID 2071: Firewall Rule Addedchevron-rightEventID 2073: Firewall Rule Modifiedchevron-rightEventID 2052: Firewall Rule Deletedchevron-right

Last updated 2 years ago