Registry Labs
Where Windows records what happened: execution evidence, registry hives, filesystem metadata, and the devices that were plugged in.
- Windows 11 Forensic Artifacts: Where Evidence of Program Execution Lives
Windows records that a program ran in at least six separate places, and they do not agree with each other. Here is what each artifact actually proves on Windows 11, and which one to trust.
Forensic artifact · Intermediate · T1057
- USB Device History on Windows 11: What the Registry Proves
Windows keeps a permanent record of every USB storage device ever attached, including serial numbers and first-connect times. Here is where it lives on Windows 11 and how to read it.
Forensic artifact · Beginner · T1052.001
- ShimCache vs Amcache vs Prefetch: Which One Proves Execution?
Three Windows artifacts get treated as interchangeable evidence that a program ran. Only one of them actually proves it. Here is what each records on Windows 11 and how to read them together.
Forensic artifact · Intermediate · T1057
- Amcache.hve on Windows 11: What It Records and How to Read It
Amcache stores the SHA-1 of executables Windows has encountered — including ones already deleted. Here is how to parse it on Windows 11 and what its entries do and do not prove.
Forensic artifact · Intermediate · T1057