Skip to content

Windows artifacts

Windows leaves a huge trail of what happens: program execution, connections, file opens, persistence, and logins are recorded across dozens of artifacts. Knowing them is what lets you reconstruct an attack even if the attacker deleted some evidence.

Prefetch (C:\Windows\Prefetch\*.pf) which executables ran, when, and how many times
Amcache / RecentFileCache executed programs, SHA1 hashes
ShimCache (AppCompatCache) executables seen (execution/presence)
UserAssist (registry) programs launched from Explorer (ROT13)
BAM/DAM execution per user with timestamp
SRUM resource/network use per application (energy, bytes)
Jump Lists / Recent / LNK files and paths recently opened
Shellbags (registry) folders browsed (even already deleted)
Recycle Bin ($Recycle.Bin) files deleted by the user
Browser history, downloads, cache (Chrome/Edge/Firefox)
Run/RunOnce keys, Startup folder classic persistence (see mal-persist)
Scheduled Tasks (\Windows\Tasks) Event 4698; tasks' XML
Services Event 7045 (new service), registry
WMI event subscriptions stealthy persistence
Security 4624/4625 successful/failed logon (type 3 network, 10 RDP)
Security 4648 logon with explicit credentials (runas, lateral)
Security 4672 special privileges assigned (admin)
Security 4688 process creation (with command line if enabled)
Security 4720/4732 account creation / added to group (privileges)
Security 1102 security log cleared! (anti-forensics)
System 7045 service installation
Sysmon rich telemetry (see def-sysmon)
PowerShell 4104 Script Block Logging (executed scripts)
SYSTEM/SOFTWARE/SECURITY/SAM + NTUSER.DAT config, persistence, user activity
# tools: RegRipper, Registry Explorer (Eric Zimmerman)
Eric Zimmerman tools MFTECmd, PECmd (prefetch), AmcacheParser, ShellBags, Registry Explorer
KAPE fast artifact collection and processing (triage)
Chainsaw / Hayabusa hunt in the Event Logs with Sigma rules
Velociraptor DFIR at scale (remote artifact collection)
  • Use KAPE to collect key artifacts fast (triage) and the EZ tools to parse them.
  • Cross execution evidence (Prefetch/Amcache/ShimCache) with Event Logs and Sysmon.
  • Watch Event 1102 (log cleared) and artifact gaps: absence is also a signal.
  • Everything feeds the timeline (Timeline analysis) and the ATT&CK mapping (MITRE ATT&CK).
  • Prefetch/Amcache/ShimCache are the basis for proving what ran in real incidents.
  • Event 1102 (log cleared) and Shadow Copy deletion are recurring ransomware TTPs before encrypting.
  • Chainsaw/Hayabusa with Sigma are used to hunt TTPs in EVTX at scale during IR.
  • Fast artifact collection (KAPE)
  • Execution evidence (Prefetch/Amcache/ShimCache/UserAssist/SRUM)
  • File-open/activity (LNK/Jump Lists/Shellbags/browser)
  • Persistence (Run keys, tasks 4698, services 7045, WMI)
  • Key Event Logs (4624/4625/4688/4720/1102) with Chainsaw/Hayabusa
  • Registry (EZ tools/RegRipper)
  • Integrate into the timeline and map to ATT&CK