Operator On The Wire
Join
← Back to Knowledge Base
BLUE TEAM / DFI / ARTEFACT / WINDOWS / REGISTRY / RegRipper

Execution Evidence

PluginHiveWhat it gives you
amcacheAmCacheExecuted programs
appcompatcacheSYSTEMShimCache execution evidence
shimcacheSYSTEMFile execution traces
bamSYSTEMBackground Activity Monitor execution
userassistNTUSER.DATGUI-launched programs
muicacheNTUSER.DAT / USRCLASSExecuted EXEs
recentappsNTUSER.DATRecent app launches
featureusageNTUSER.DATApp usage counters
syscacheSysCache.hveExecution evidence
prefetchSYSTEMPrefetch config only (not PF contents)
comdlg32NTUSER.DATOpen/save dialog files
recentdocsNTUSER.DATOpened documents
jumplistdataNTUSER.DATJump list references
mmcNTUSER.DATOpened MMC files
runmruNTUSER.DATRun dialog commands