Back to product
PUBLIC FIELD REFERENCE

Common Windows Artifact Locations

Use these locations as investigation leads, not conclusions. Paths, retention, parsing behavior, and evidentiary meaning vary by Windows version, account context, application version, and collection method.

PUBLIC OPERATIONAL REFERENCE

High-value starting points

ArtifactCommon locationOperational use
Windows event logs%SystemRoot%\System32\winevt\Logs\Authentication, service, policy, PowerShell, and system activity, subject to enabled channels and retention.
Registry system hives%SystemRoot%\System32\config\System configuration, services, devices, networking, accounts, and other machine-level context.
User registry hives%UserProfile%\NTUSER.DAT and AppData\Local\Microsoft\Windows\UsrClass.datUser-specific execution, interaction, shell, and application context.
Prefetch%SystemRoot%\Prefetch\Potential program execution and referenced-file context when Prefetch is enabled.
LNK files%AppData%\Microsoft\Windows\Recent\References to opened files, volumes, paths, and associated metadata.
Jump Lists%AppData%\Microsoft\Windows\Recent\AutomaticDestinations\Application-centric recent-item and destination references.
Recycle Bin$Recycle.Bin\<SID>\Deleted-item metadata and retained file content when present.
SRUM%SystemRoot%\System32\sru\SRUDB.datApplication, network, and resource-usage context, subject to version and parser support.

Validation questions

  • Was the artifact collected from the live system, a forensic image, a volume shadow copy, or another source?
  • What operating-system build, account SID, timezone, and clock condition apply?
  • Was the feature enabled and was retention sufficient for the relevant period?
  • Does the parser expose source fields and limitations, and can important findings be independently checked?
  • What alternative explanations fit the same artifact?
Interpretation limit

An artifact may support activity, configuration, or association without proving who performed the action or why.

Continue with the complete workflow

Public references are starting points. DFIR Field Toolkit connects operational references with an encrypted local case record, evidence inventory, field forms, amendments, and exports.

Create one complete case free or explore the synthetic product demo.