11.1 Windows Endpoint Forensics and Volatile Artifact Analysis
Key Takeaways
NTFS metadata structures—specifically the $MFT, $LogFile, and $UsnJrnl—provide complementary, retention-limited records of file activity; discrepancies between $STANDARD_INFORMATION and $FILE_NAME attributes.
Windows execution analysis must triangulate artifacts: Prefetch can record run counts and timestamps, BAM/DAM can indicate recent per-user execution, and Shimcache generally supports file-presence or compatibility evidence but alone does not prove execution.
Shellbags, LNK files, Jump Lists, and RecentDocs can support inferences about folder navigation and file interaction, including removable media, but should be correlated before attributing deliberate user action.
Windows event auditing provides high-value telemetry through Event IDs 4624, 4625, 4688 when enabled, 7045, and PowerShell 4104 when configured; retention, policy, and tampering affect completeness.
Targeted collection with KAPE or Velociraptor can acquire selected high-value artifacts faster than full-disk imaging; acquisition time and volatile coverage depend on the target, tool, permissions, and collection plan.
Windows Endpoint Forensics and Volatile Artifact Analysis
Incident handling on Windows endpoints requires deep knowledge of file system metadata, execution tracking, and event auditing. Because Windows hosts represent primary targets for initial access, privilege escalation, and lateral movement, responders must extract and correlate high-fidelity artifacts under crisis conditions. Intruders frequently leverage living-off-the-land binaries, in-memory execution, and timestomping to conceal activity. Handlers must triangulate forensic evidence across file systems, registry hives, and event logs to establish proof of presence, execution, and user interaction.
Low-Level NTFS File System Artifacts
The New Technology File System (NTFS) maintains low-level metadata tracking file lifecycle events:
- Master File Table ($MFT): Structural core of NTFS allocating a 1024-byte record per file and folder. Key attributes include:
- $STANDARD_INFORMATION ($SI): Stores DOS permissions and MACB (Modified, Accessed, Created/Born, Entry Modified) timestamps. Because user-mode APIs like SetFileTime can modify $SI, adversaries and tools like Cobalt Strike or timestomp alter it to blend into system directories.
- $FILE_NAME ($FN): Stores file name, namespace, parent directory reference, and independent MACB timestamps. The $FN attribute is updated only by the NT kernel during file operations (renaming, creating, moving). Handlers detect timestomping by identifying discrepancies where $SI timestamps are backdated while $FN timestamps record true creation times.
- $LogFile: Circular transaction log in the volume root recording metadata changes (cluster allocation, index updates) to ensure consistency during crashes. Handlers inspect it to track immediate pre-incident file transactions.
- $UsnJrnl (Update Sequence Number Journal): Stored in $Extend as the $J alternate data stream, $UsnJrnl logs file and directory modifications, deletions, renames, and attribute shifts. Because records persist after file deletion and $MFT record reuse, it provides vital evidence of deleted staging archives, scripts, or malware droppers.
- Volume Shadow Copies (VSS): Differential block-level snapshots created by the Volume Snapshot Service. Handlers query snapshots using vssadmin list shadows to recover pre-attack file states, deleted tools, and registry hives prior to ransomware encryption.
Program Execution Artifacts and Triangulation
Proving an executable was present on disk does not prove execution. Handlers triangulate evidence across multiple execution artifacts:
- Prefetch (.pf files): Windows Cache Manager creates Prefetch files in
C:\Windows\Prefetch\to optimize launch performance. Named after the executable plus an 8-character path hash (e.g., CMD.EXE-A1B2C3D4.pf), Prefetch records run count, last launch time, and—in Windows 10/11—up to seven prior execution timestamps (eight runs total). It also lists loaded DLLs and dependencies from the first 10 seconds of runtime. - Shimcache (AppCompatCache): Located in the SYSTEM hive under
CurrentControlSet\Control\Session Manager\AppCompatCache, Shimcache tracks application compatibility. Written to disk upon shutdown or restart, it records full paths, file sizes, last modified timestamps, and compatibility flags. In modern Windows, a Shimcache entry supports that a path and file metadata were observed by the compatibility mechanism, but it does not by itself prove execution or current file presence. Handlers must corroborate Shimcache with execution artifacts. - Amcache.hve: A dedicated hive at
C:\Windows\appcompat\Programs\Amcache.hverecording installed applications and portable executables (PEs). It captures SHA-1 hashes, compile timestamps, file sizes, PE header details, and installation times, enabling hash recovery of deleted binaries. - UserAssist Registry Keys: Stored in NTUSER.DAT under
Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{GUID}\Count. Tracking GUI-launched programs via Windows Explorer, value names are ROT13-encoded. Decoded entries reveal executable paths, run counts, and the last execution FILETIME timestamp per user. - BAM and DAM (Background / Desktop Activity Moderator): Located in
SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\{SID}, this service manages application power consumption, recording the full path and 64-bit FILETIME of last execution per user SID.
File Opening, Access, and Folder Browsing Artifacts
Reconstructing file access and interactive directory traversal relies on specific access artifacts:
- LNK Shortcut Files: Stored in
%APPDATA%\Microsoft\Windows\Recent\, LNK files generate automatically when documents are opened. They record target paths, file sizes, volume serial numbers, target MACB timestamps, and host NetBIOS names, proving file access even if stored on detached USB drives. - Shellbags: Stored in UsrClass.dat under
Local Settings\Software\Microsoft\Windows\Shell\Bagsand BagsMRU, Shellbags retain folder view preferences and namespace artifacts from Windows Explorer. They can indicate that a folder was represented or browsed in an Explorer context, supporting reconstruction of directory traversal across local drives, network shares, and removable media, even after folders are deleted. - Jump Lists: Located in
%APPDATA%\Microsoft\Windows\Recent\AutomaticDestinations\andCustomDestinations\, Jump Lists store application-specific Most Recently Used (MRU) records in MS-SHLLINK compound format, documenting recent documents opened within specific programs. - RecentDocs: Registry key in NTUSER.DAT tracking recently opened files grouped by extension in MRU order.
Windows Event Log Analysis
The Windows Event Log repository (C:\Windows\System32\winevt\Logs\) provides high-fidelity auditing:
- Security Log Event IDs:
- 4624 (Successful Logon): Evaluates logon mechanisms via LogonType: Type 2 (Interactive console), Type 3 (Network logon—SMB, RPC, PsExec), Type 4 (Batch), Type 5 (Service), Type 7 (Unlock), Type 9 (NewCredentials), Type 10 (RemoteInteractive—RDP), and Type 11 (CachedInteractive).
- 4625 (Failed Logon): Detects brute-force attacks via failure codes: 0xC000006A (bad password), 0xC0000064 (invalid user), and 0xC0000234 (account locked).
- 4672 (Special Privileges Assigned): Documents administrative logons assigning high-privilege tokens (e.g., SeDebugPrivilege).
- 4688 (Process Creation): Documents process execution. With Command Line Auditing enabled, it records process names, parent processes, and exact CLI arguments.
- 4720 (User Created) & 4726 (User Deleted): Detects unauthorized account creation or deletion for persistence.
- 7045 (System Log: New Service Installed) & 4697 (Security Log): Detects service persistence and remote execution utilities (e.g., PsExec PSEXESVC).
- 1102 (The Audit Log Was Cleared): High-severity indicator of adversary anti-forensics.
- PowerShell Auditing: When enabled, Script Block Logging (Event ID 4104) records PowerShell script blocks and often captures content after PowerShell has decoded or assembled it; it is not guaranteed to be complete or immune to evasion and tampering. Module Logging (Event ID 4103) and Transcription logging record pipeline executions and terminal sessions.
Live Triage Frameworks and Rapid Acquisition
Dead-box forensic imaging introduces intolerable latency during active breaches. Responders deploy live triage tools:
- KAPE (Kroll Artifact Parser and Extractor): Employs Targets (.tkape) to extract high-value artifacts (MFT, registries, logs, Prefetch) in minutes, and Modules (.mkape) to run parsers.
- Velociraptor: An endpoint visibility and forensics platform using Velociraptor Query Language (VQL) to hunt IoCs, query registries, dump memory, and extract artifacts at enterprise scale.
- FTK Imager: Standard tool for acquiring forensically sound physical and logical images, memory dumps, and generating SHA-256 evidence hashes.
During an intrusion investigation on a Windows 11 endpoint, a digital forensics analyst discovers an entry for an unauthorized administrative executable named psexec_svc.exe in the Shimcache (AppCompatCache) registry key. However, the analyst does not find an associated Prefetch file, and BAM registry keys contain no record of the executable. What is the most accurate forensic interpretation of these findings?
The file existed on the endpoint and was evaluated by the Windows Application Compatibility engine, but Shimcache alone does not prove the file was executed.
The file was definitely executed multiple times because Shimcache records execution counts and memory injection signatures.
The operating system corrupted the Prefetch directory, confirming that the attacker deployed a kernel rootkit to erase BAM telemetry.
The executable was run inside an encrypted volume that prevented Windows from recording execution timestamps in the Master File Table.
An incident responder analyzes Windows Security event logs following a suspected lateral movement campaign. The responder identifies Event ID 4624 associated with a compromised administrative account. The event details show LogonType = 3 originating from an internal IP address 10.0.4.15 over port 445. Which logon activity does this event represent?
An interactive console logon where an operator physically logged in at the workstation keyboard
A network logon established across the network, characteristic of SMB shares, RPC, or PsExec activity
A remote desktop interactive session established using the Remote Desktop Protocol (RDP)
A service startup logon initiated by the Windows Service Control Manager
A forensic investigator suspects an adversary connected an unauthorized USB drive to a Windows workstation, browsed several internal accounting folders, and opened a sensitive spreadsheet named payroll_2026.xlsx. Although the external drive was removed and the spreadsheet was never saved to the local C: drive, which Windows forensic artifacts can substantiate that the user navigated through those specific folders and accessed that document?
Master Boot Record (MBR) partition tables and system BIOS configuration tables
Active Directory Kerberos ticket-granting service (TGS) requests and DNS resolver caches
Shellbags to indicate folder navigation, correlated with LNK files and Jump Lists supporting document access
PowerShell Transcription logs and Windows Defender signature update repositories
Sections you finish are checked off in the contents.