Windows
Interactive Session
This section is for artifacts which are created when a user has an interactive desktop session, either sitting at the system or via a remote desktop session.
Run Box
RunMRU - Provides list of commands executed via the Run Box
|
Documents
File MRU/Place MRU - Provides list of office documents opened with path
|
Windows Explorer
TypedPaths - Provides list of paths typed by user in the Windows Explorer
OpenSaveMRU/LastVisitedMRU - Provides list of opened and saved files accessed via dialog boxes
UserAssist - Provides list of programs executed by user via Explorer Window
TypedURLs - Provides a list of URL's and Paths typed in the Windows Explorer or Internet Explorer address bars
|
Internet Explorer
TypedURLs - Provides a list of URL's and Paths typed in the Windows Explorer or Internet Explorer address bars
|
Windows Search
ACMru - Contains list of recent search terms used in the Windows Search functionality; Four different subkeys exists for Internet Search, Windows Files, word or phrase search, and people/computer search Location: HKCU\Software\Microsoft\Search Assistant\ACMru |
AutoStart
Contains a list of artifacts related to anything that starts on its on such as a scheduled task or startup item.
On Start Up
Autorun - Contains paths to items that execute at system startup
RunOnce - Contains list of programs that will run at startup only once
Run Services - Contains a list of services that start automatically
Services
Services - Contains a list of all services, active and non-active
|
Cmd.exe
Command Processor Autorun - Contains a list of commands that are executed every time cmd.exe runs
|
Networking/Shares
This section contains artifacts related to networking and user shares.
Networked Drives
Map Network Drive MRU - Contains list of recently mapped network drives
MountPoints2 - Contains list of all drives that have been mounted (both physical and network); requires cross correlation with MountedDevices
|
USB
Contains list of arti
USB Storage
USBSTOR - Stores list of mounted USB devices
|
References
I didn't come up with any of this material. I pulled from the various resources below and organized them in a way that made it easier to reference for me. I appreciate all of there hardwork and urge you to check out there blogs.
Andreafortuna.org
Andreafortuna.org