Windows artifacts
Windows leaves a huge trail of what happens: program execution, connections, file opens, persistence, and logins are recorded across dozens of artifacts. Knowing them is what lets you reconstruct an attack even if the attacker deleted some evidence.
Execution evidence
Section titled “Execution evidence”Prefetch (C:\Windows\Prefetch\*.pf) which executables ran, when, and how many timesAmcache / RecentFileCache executed programs, SHA1 hashesShimCache (AppCompatCache) executables seen (execution/presence)UserAssist (registry) programs launched from Explorer (ROT13)BAM/DAM execution per user with timestampSRUM resource/network use per application (energy, bytes)File-open / user-activity evidence
Section titled “File-open / user-activity evidence”Jump Lists / Recent / LNK files and paths recently openedShellbags (registry) folders browsed (even already deleted)Recycle Bin ($Recycle.Bin) files deleted by the userBrowser history, downloads, cache (Chrome/Edge/Firefox)Persistence (where to look)
Section titled “Persistence (where to look)”Run/RunOnce keys, Startup folder classic persistence (see mal-persist)Scheduled Tasks (\Windows\Tasks) Event 4698; tasks' XMLServices Event 7045 (new service), registryWMI event subscriptions stealthy persistenceKey Event Log entries
Section titled “Key Event Log entries”Security 4624/4625 successful/failed logon (type 3 network, 10 RDP)Security 4648 logon with explicit credentials (runas, lateral)Security 4672 special privileges assigned (admin)Security 4688 process creation (with command line if enabled)Security 4720/4732 account creation / added to group (privileges)Security 1102 security log cleared! (anti-forensics)System 7045 service installationSysmon rich telemetry (see def-sysmon)PowerShell 4104 Script Block Logging (executed scripts)Registry (hives)
Section titled “Registry (hives)”SYSTEM/SOFTWARE/SECURITY/SAM + NTUSER.DAT config, persistence, user activity# tools: RegRipper, Registry Explorer (Eric Zimmerman)Eric Zimmerman tools MFTECmd, PECmd (prefetch), AmcacheParser, ShellBags, Registry ExplorerKAPE fast artifact collection and processing (triage)Chainsaw / Hayabusa hunt in the Event Logs with Sigma rulesVelociraptor DFIR at scale (remote artifact collection)Blue Team / DFIR
Section titled “Blue Team / DFIR”- Use KAPE to collect key artifacts fast (triage) and the EZ tools to parse them.
- Cross execution evidence (Prefetch/Amcache/ShimCache) with Event Logs and Sysmon.
- Watch Event 1102 (log cleared) and artifact gaps: absence is also a signal.
- Everything feeds the timeline (Timeline analysis) and the ATT&CK mapping (MITRE ATT&CK).
Real-world cases
Section titled “Real-world cases”- Prefetch/Amcache/ShimCache are the basis for proving what ran in real incidents.
- Event 1102 (log cleared) and Shadow Copy deletion are recurring ransomware TTPs before encrypting.
- Chainsaw/Hayabusa with Sigma are used to hunt TTPs in EVTX at scale during IR.
Testing checklist
Section titled “Testing checklist”- Fast artifact collection (KAPE)
- Execution evidence (Prefetch/Amcache/ShimCache/UserAssist/SRUM)
- File-open/activity (LNK/Jump Lists/Shellbags/browser)
- Persistence (Run keys, tasks 4698, services 7045, WMI)
- Key Event Logs (4624/4625/4688/4720/1102) with Chainsaw/Hayabusa
- Registry (EZ tools/RegRipper)
- Integrate into the timeline and map to ATT&CK