Windows Artifacts
Default Path for System and User Profile Folder
Folder Structure
Important for examiners to be familiar with the operating system artifacts and their default locations for each versions
Operating System | Default System Folder | User Profile Folders |
---|---|---|
Windows 2000 | C:\WINNT |
C:\Documents and Settings |
Windows XP | C:\Windows |
C:\Documents and Settings |
Windows Vista/7/8/10 | C:\Windows |
C:\Users |
Important Folders/Files
Folder/Files | Subfolders/files | Path | Description |
---|---|---|---|
Root |
|
|
|
Windows 2000/XP Recycler Windows Vista/7/8/10/11 $Recycle.bin |
|
C:\Users\%UserName%\$RECYCLE.BIN\<SID>
|
|
Low Folders |
|
|
|
Cookies Folder |
|
|
|
Temporary Internet Files (TIF) |
Earlier Windows OS
|
|
|
Email Folder |
Windows 10
|
||
Recent Folder |
C:\Users\%UserName%\AppData\Roaming\Microsoft\Windows\Recent
|
|
|
My Documents |
C:\Users\%UserName%\Documents
|
|
|
Sent To Folder |
C:\Users\%UserName%\AppData\Roaming\Microsoft\Windows\SendTo
|
|
|
Temp Folder |
C:\Users\%UserName%\AppData\Local\Temp
|
|
|
Desktop Folder |
C:\Users\%UserName%\Desktop
|
|
NTUSER.DAT
- Every user profile has an NTUSER.DAT file
- It is a registry file
- Updated by the OS once the user logs out
- Last written time can be used to pin point user last log out time
- Requires registry viewer to view the contents
Cookies
- Examiners can use cookie decoder to decode the cookie and examine the contents
- Cookie can be used for:
- Authentication
- Storing site preferences
- Shopping cart contents
- Identifier for a server-based session
- Index.dat
- file is a database file that contains the data about each cookie and pointers to the cookie file to the originating website name
- Contains dates and the cookie itself contains its own internal date
- Internal dates can show last modified by the website and its expiration date
Send To Folder
- Default selections include:
- Documents
- Desktop
- Mail Recipient
- Drives
- Applications may add additional options to this folder and users has the ability to create entries in this folder
Web Browsers
Browser | Favorites Path | Bookmarks Path | History Path | Cookies Path | Additional Information |
---|---|---|---|---|---|
Internet Explorer | C:\Users\%UserName%\Favorites |
C:\Users\%UserName%\AppData\Local\Microsoft\Windows\History History.IE5 Low\History.IE5 |
C:\Users\%UserName%\AppData\Roaming\Microsoft\Windows\Cookies C:\Users\%UserName%\AppData\Roaming\Microsoft\Windows\Cookies\Low |
||
Google Chrome | C:\Users\%UserName%\AppData\Local\Google\Chrome\User Data\Default\ |
C:\Users\%UserName%\AppData\Local\Google\Chrome\User Data\Default\ |
C:\Users\%UserName%\AppData\Local\Google\Chrome\User Data\Default\ |
Files use SQLite database format | |
Mozilla Firefox | C:\Users\%UserName%\AppData\Roaming\mozilla\Firefox\Profiles\xx.default\places.sqlite |
C:\Users\%UserName%\AppData\Roaming\mozilla\Firefox\Profiles\xx.default\places.sqlite |
C:\Users\%UserName%\AppData\Roaming\mozilla\Firefox\Profiles\xx.default\places.sqlite |
Files use SQLite database format |
Online Communication Tools
Application | History/Conversations Path |
---|---|
Skype | C:\Users\%UserName%\AppData\Roaming\Skype\<aliases>\main.db |
MS Team | Office 365 Group Mailbox Conversation History\Team Chat Private Chats User's Mailbox\Conversation History\Team Chat |
Last update:
June 11, 2023
Created: June 11, 2023
Created: June 11, 2023