Operator On The Wire
Join
← Back to Knowledge Base
BLUE TEAM / DFI / ARTEFACT / WINDOWS / DELETED

Pagefile.sys

When files are deleted from an NTFS file system volume, their MFT entries are marked as free and may be reused, but the data may remain on the disk until overwritten. That’s why recovery isn't always possible.

Use Keyword Search for:

  • password
  • Authorization
  • Bearer
  • cmd.exe
  • powershell
  • rundll32
  • http
  • https
  • suspicious IPs
  • domain names
  • known IOCs

Pagefile often contains:

  • Cleartext credentials from memory
  • Fragments of C2 configs
  • Shellcode remnants