⏹️

Windows Forensics

Windows Forensics Cheat Sheets

Windows File System

Windows Event Logs

Windows Registry Forensics

Windows Monitoring techniques

AmCache

  • An artifact which stores metadata related to PE execution and program installation on Windows