12.1 Windows Artifacts Part 1

Video Activity
Join over 3 million cybersecurity professionals advancing their career
Sign up with
Required fields are marked with an *

Already have an account? Sign In »

4 hours 15 minutes
Video Transcription
Hello, well comfortable 12. The window system stores different types off evidence they control the user's activity on the computer systems. Most off the forensic investigations would revolve around traditional areas. So shall user created or use our protected data like active or delay of five
bus works.
It's great that files among olders but nor around nontraditional areas such as system created data or artifacts.
Artifacts are objects or areas within a computer system that whole important information relevant to the activities performed on the computer by the user.
The location on type of information contained in the artifacts differs from one operating system to another.
These artifacts have to be identified properly. Process on information contained in there has to be analysed, toe proof or this process on observation made during the forensic analysis.
However, absence of information in a particular artifact doesn't mean that this did not occur in the computer system.
They're in multiple artifacts in a window's environment that serves as important evidence. In the forensic analysis off StarMedia,
we have seen it produced models. Some of this in just such as the windows profess the right history. We're still points are sore this morning, We're analyzing the folder structure on a windows upgrade your sister. This can provide important evidence. So if you want to analyze some of the windows Seychelles,
your first post this video
have you the previous models.
We know spreading system creates multiple artifacts because officer TV on the computer system. When a user looks on for the first time, a series off folders files are created on that computer. In a way, there is trust parents to the user.
This folder structure is created whether the person looks on luckily, or attempt a case through a network.
On interesting thing about this process is that the user's root folder off their structure is named after the person's use her name.
Well, not lt 2000. Expedient to those sultry on Vista, all store these folders in different places.
When those 2000 expecto sentry is stored information in C document and settings
windows lt distorts tendency. Will Auntie pra fais on Willis the starry some very sense. It starts in the folder. You see users
they account for all users is one that should be included in all examinations.
As this account is accessible to all on holds global information. The root folder for a user also contains anti user does that, which is a key file mentioned in previous various the anti user does that is updated by the Veridian system. When I used to look out,
it's last return. Town can be used to possible determine when the user last looked out.
Okay, here's a quick question for you.
Where's the users who folded, located in modern versus off windows? Is it a C documents on settings or B C Will NT pra fires or C C users or probably D C NT users?
If you said see you're correct.
A is a location for Williams to south on Expedia. Onto the tree
be represents the folder word that Window's NT store. The user's data. Andi is not a real sister folder.
When does the stuff on recent versions stores the uses data? You see users. Now let's analyze some of the artifacts.
The application data or update a folder contains they created by protests. Almost every program you still create is unfolding in up data on the stores. Information there,
Invista moments and very sprints off Windows de Application Data Folder, Hospital Place with our folder named up data. The AFT later forced their size in the user folder, which is the same location. The contents documents music on order like very folders.
Normally, this is something social, sexy user. Use her name up data, but like those folders up data is healing, which means you can't normally see it.
The Windows Address book is located within the folder found within this area,
a least off recently accessed files created or open through only Microsoft Office application is maintained under application. Daya Microsoft Office Re Sent folder
If you're using an older person off our look,
that brutal stada is probably in update as well.
A cookie is a small piece off data sent by a server toe. A browser on stored on the uses computer while the user is Rosie
Cookies are produced a shared between the Brosa under server using the STD Ba heather.
It allows server store under trees later from the clients. It is stored in a fire on the tri inside on the maximum size off cookie that can be stored is limited upto for killer vice in anywhere. Brosa
Internet site typically store cookies from local computers to allow identification off the user on subsequent visits.
Cookies can be not allowed by the user but are mostly accepted. The overuse value to forensic analysis is to be able to gain an insight to the size they use services.
Days, sometimes off the visit, are also useful.
Forest us Will You Open? You took on search for pop songs. This will get saved in your grocer's history. Now, the next time you go toe to toe in the grocer, the cookies read your browsing history, and you will be recommended. More pop songs
in older versions of Windows. The Cookies folder is located in the Road User folder
with this Beast. Our recent versions because cookies followed the user in our domain. The Cookies folder is found at sea. You, sir, User name. After data roaming Microsoft, we lose cookies
on windows. The next stop is the location, which occupies the whole screen area that you see after you sign into your user account.
He can store Sure could tow anything as well as five folders
finds you see on the deck stop are stored in a special folder in the user profile.
All the fires present on the deck stop off a user are stored in the Dexter folder off the braiding sister. Deeply, the death star is populated either by the user or buy programs that automatically create five I'm placed in on the desktop.
The old user's desktop should also be examined to see what I come for Global on what once are specific to the user
in more Windows versions in Turin, Windows 10 All You first folder has been replaced by a folder called Public the Dexter Fold. Their contents are stored in two locations.
One is the common Dex Stop located in the full there. See you, sirs Bolic deck stop on the other one is a special folder in the current user's profile.
You see you thirst username on destiny.
Windows shows the content off both folders in a single view.
The favourites fold. They're found in Windows provides the user on easy way to organize on launch the folders that they used often
the favourites fold there was introduced in Greendale, seven on continues and Windows eight More recent versus displayed in the left side. Bar Favors provides easy access to popular locations within the Explorer.
This folder contains favourites for Internet Explorer
Intimate size that I use service is frequently are typically found in this folder.
Examiners should be aware that some scripts contain with S T. M L Vegas can populate entries with this folder without the use is consent.
Why the majority of entries are due to the action off. The user's additional examination may be required to confirm the origin
by default. We know stores the user's personal favorites folder in the user's account folder
More window So pretty insistent stores favorites in See You, sir, You, sir Noon favourites.
Okay, In the next video, we'll keep bringing in some off the windows artifacts. And in the meantime, don't forget to check the references and supplementals if you want to know more about this window's artifacts.
Up Next