Forensic CheatSheet
/
Artifacts
Artifacts
ALL
Windows
Linux
MACOS
Misc
Search
Name
Category
Sub-Category
Description(Summary)
Modified Time
Created Time
Writer
Read Time(min)
Prefetch & Superfetch
Open
Windows
file-execution
Window XP부터 지원
2023/04/11 07:52
2022/09/28 00:14
안상혁
9
LNK file
Open
Windows
file-execution
2023/03/20 05:00
2022/09/28 00:14
안상혁
9
SRUM
Open
Windows
Network Usage
file-execution
Volatile Data
Window 8부터 지원
2023/03/20 05:00
2023/01/17 07:11
안상혁
9
RecycleBin
Open
Windows
File Recovery
2023/03/20 05:00
2022/09/28 00:14
안상혁
11
Shellbag
Open
Windows
Registry
Folder-Access
User-Activity
Windows 10
2023/03/20 05:01
2023/01/27 13:06
안상혁
20
Jumplist
Open
Windows
file-execution
User-Activity
Window 7 이후
2023/03/20 05:01
2023/03/12 12:01
안상혁
14
ThumbCache / IconCache
Open
Windows
file-execution
User-Activity
Deleted-File
Media
2023/04/05 07:27
2023/03/18 05:05
안상혁
12
ADS(Alternative Data Stream)
Open
Windows
Hidden Data
File-Download
Malware
Windows NT 3.1 이후 지원
2023/05/31 12:42
2023/05/02 13:33
안상혁
12