Chapter 4

File Analysis

Chapter Outline

Information in this chapter

• MFT

• Event Logs

• Recycle Bin

• Prefetch Files

• Scheduled Tasks

• Jump Lists

• Hibernation Files

• Application Files

Introduction

As with any computer system, Windows systems contain a great number of files, many of which are not simply a standard ASCII text format. Many of these files may not have any relevance to the analysis at all, and only a few may provide critical information to the analyst. There also may be a number of files that are unknown ...

Get Windows Forensic Analysis Toolkit, 3rd Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.