Free Tool

Windows Forensic Artifacts Reference

Every artifact a responder needs. Categorized. With registry paths, tools, and investigative context.

Seven artifact categories covering what attackers leave behind on Windows systems — persistence mechanisms, program execution evidence, file and folder activity, user account usage, network indicators, USB device history, and event log forensics. Each artifact includes the registry path or file location, the tool to extract it, what it proves, and what to look for during an investigation.

For the full investigation methodology — how to interpret these artifacts in context, build investigation timelines, and reconstruct attack chains — see the Windows Endpoint Investigation course (WF2: What Ran on This System, WF3: Who Was Here and What Did They Do, WF7: What Happened on the Filesystem) and the Incident Triage course (TR4: Endpoint Triage). Start the free Windows forensics modules →

Weekly security engineering insights

Detection techniques, architecture patterns, and operational judgment, every Tuesday.

No spam. Unsubscribe anytime.