Windows Artifact Forensics: Registry, Execution Evidence & Filesystem Metadata
A Windows system keeps writing evidence of what it did long after the disk image from Chapter 2 is acquired. Execution history, folder browsing, and file access get scattered across the registry, the filesystem, and the event logs. This chapter walks the highest-value artifact types and how to read them.
The Registry as Evidence
The Windows registry is not just configuration storage. Its hives hold a running record of accounts, services, installed software, and per-user activity that survives well past the session that created it.
| Hive | Forensic Value |
|---|---|
| SAM | Local user accounts on the machine |
| SYSTEM | Services, devices, and computer configuration |
| SOFTWARE | Installed applications, some execution evidence |
| NTUSER.DAT | Per-user settings and activity, loaded from each user's profile |
| UsrClass.dat | Per-user shell and COM activity, shellbags live here |
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer in NTUSER.DAT: UserAssist, which records GUI program launches along with a run count, with the value names ROT-13 encoded, and RunMRU, which records commands typed into the Run dialog in most-recently-used order.
Execution and Usage Evidence
Beyond the registry, Windows leaves a second layer of usage evidence in dedicated system files. Each artifact type proves a slightly different claim about what happened on the machine.
| Artifact | What It Proves |
|---|---|
| Prefetch | A program was executed, and roughly how many times and when it last ran |
| Shellbags | A folder was browsed in Explorer, even if it was later deleted |
| Jump Lists / LNK files | A specific file was opened, often including the original file path even after the file moves |
| Recent Documents | A file was recently accessed by the user |
Filesystem Metadata
Every file on an NTFS volume carries timestamps, commonly summarized as MACB: Modified, Accessed, Changed (metadata change), and Born (created). Reading these correctly is central to placing activity in time.
- Modified: file content was last written
- Accessed: file was last opened or read
- Changed: file metadata (permissions, name, attributes) was last altered
- Born: file was originally created
NTFS actually keeps two separate sets of these timestamps: one in $STANDARD_INFORMATION and one in $FILE_NAME. Most tools show you the first set by default, but the second exists too, and the gap between them matters for spotting tampering, a topic Chapter 5 covers in full.
Event Log Forensics
Windows event logs are stored in the EVTX format and record system, security, and application activity as discrete numbered events. A handful of Event IDs carry outsized forensic value.
| Event ID | What It Represents |
|---|---|
| 4624 / 4625 | A successful or failed logon |
| 4688 | A new process was created |
| 4720 | A new user account was created |
Correlating Artifacts Into a Story
No single artifact stands on its own as proof. A defensible finding comes from lining several artifact types up against the same event and checking that they agree.
No single artifact here is proof by itself. Correlation across artifact types is what turns a set of clues into a defensible finding.
Key Takeaways
- Registry hives each hold a different slice of evidence: SAM for accounts, SYSTEM for configuration, SOFTWARE for installed apps, NTUSER.DAT and UsrClass.dat for per-user activity.
- UserAssist and RunMRU are well-documented registry keys that record GUI launches and typed commands.
- Execution and usage artifacts like Prefetch, Shellbags, Jump Lists, LNK files, and Recent Documents each prove a distinct claim about what the user did.
- NTFS timestamps are commonly summarized as MACB, and the filesystem keeps two separate copies, in $STANDARD_INFORMATION and $FILE_NAME, which matters for detecting tampering.
- The USN Journal can show filesystem activity even after the files involved are gone.
- EVTX event logs, especially IDs like 4624/4625, 4688, and 4720, anchor artifacts to specific logon sessions and users.
- No artifact type is conclusive alone. Correlating registry, execution, filesystem, and event log evidence together is what builds a defensible narrative.
Knowledge Check
Click an answer to reveal the explanation.
Shellbags are most useful for proving which of the following?
What does the presence of a Prefetch file for an executable most directly indicate?
Why does it matter that NTFS keeps timestamps in both $STANDARD_INFORMATION and $FILE_NAME?