πŸ”
Windows Forensic Handbook
search
Ctrlk
πŸ”
Windows Forensic Handbook
  • πŸ‘‹Welcome
  • Artifacts by Type
    • πŸ—„οΈRegistry Artifacts
      • Amcache.hve
      • Background Activity Montitor
      • Image File Execution Options Registry Keys
      • System Resource Usage Monitor (SRUM)
      • Run/RunOnce Registry Keys
      • Tracing Registry Keys
      • Services Registry Keys
      • Select Registry Key
      • CurrentVersion Registry Key
      • ComputerName Registry Key
      • Interfaces Registry Key
      • NetworkCards Registry Key
      • TimeZoneInformation Registry Key
    • πŸ“‚Filesystem Artifacts
    • πŸ“…Event Log Artifacts
  • Artifacts by Activity
    • πŸƒβ€β™‚οΈExecution
    • πŸ—’οΈFile Activity
    • πŸ‘¨β€πŸ”§Account Activity
    • 🌎Network Activity
    • πŸ”Browser Activity
    • πŸ–₯️System Enumeration
gitbookPowered by GitBook
block-quoteOn this pagechevron-down
  1. Artifacts by Type

πŸ—„οΈRegistry Artifacts

Amcache.hvechevron-rightBackground Activity Montitorchevron-rightImage File Execution Options Registry Keyschevron-rightSystem Resource Usage Monitor (SRUM)chevron-rightRun/RunOnce Registry Keyschevron-rightTracing Registry Keyschevron-rightServices Registry Keyschevron-rightSelect Registry Keychevron-rightCurrentVersion Registry Keychevron-rightComputerName Registry Keychevron-rightInterfaces Registry Keychevron-rightNetworkCards Registry Keychevron-rightTimeZoneInformation Registry Keychevron-right

Last updated 2 years ago