Execution Artifacts Labs
Where Windows records what happened: execution evidence, registry hives, filesystem metadata, and the devices that were plugged in.
- Windows 11 Forensic Artifacts: Where Evidence of Program Execution Lives
Windows records that a program ran in at least six separate places, and they do not agree with each other. Here is what each artifact actually proves on Windows 11, and which one to trust.
Forensic artifact · Intermediate · T1057
- SRUM on Windows 11: Reconstructing App, Network and Power Use
SRUDB.dat records how much data each application sent and received, hour by hour, for around 30 days. It is the only standard Windows artifact that ties a program to network volume.
Forensic artifact · Intermediate · T1020
- ShimCache vs Amcache vs Prefetch: Which One Proves Execution?
Three Windows artifacts get treated as interchangeable evidence that a program ran. Only one of them actually proves it. Here is what each records on Windows 11 and how to read them together.
Forensic artifact · Intermediate · T1057
- Prefetch Files on Windows 11: Proving a Program Ran, and When
A .pf file records how many times a program ran and the last eight times it happened. Here is how to read Prefetch on Windows 11, and the three ways the evidence misleads you.
Forensic artifact · Beginner · T1057
- Amcache.hve on Windows 11: What It Records and How to Read It
Amcache stores the SHA-1 of executables Windows has encountered — including ones already deleted. Here is how to parse it on Windows 11 and what its entries do and do not prove.
Forensic artifact · Intermediate · T1057