Windows Artifacts
Default Path for System and User Profile Folder
Folder Structure
Important for examiners to be familiar with the operating system artifacts and their default locations for each versions
| Operating System | Default System Folder | User Profile Folders |
|---|---|---|
| Windows 2000 | C:\WINNT |
C:\Documents and Settings |
| Windows XP | C:\Windows |
C:\Documents and Settings |
| Windows Vista/7/8/10 | C:\Windows |
C:\Users |
Important Folders/Files
| Folder/Files | Subfolders/files | Path | Description |
|---|---|---|---|
| Root |
|
|
|
| Windows 2000/XP Recycler Windows Vista/7/8/10/11 $Recycle.bin |
|
C:\Users\%UserName%\$RECYCLE.BIN\<SID>
|
|
| Low Folders |
|
|
|
| Cookies Folder |
|
|
|
| Temporary Internet Files (TIF) |
Earlier Windows OS
|
|
|
| Email Folder |
Windows 10
|
||
| Recent Folder |
C:\Users\%UserName%\AppData\Roaming\Microsoft\Windows\Recent
|
|
|
| My Documents |
C:\Users\%UserName%\Documents
|
|
|
| Sent To Folder |
C:\Users\%UserName%\AppData\Roaming\Microsoft\Windows\SendTo
|
|
|
| Temp Folder |
C:\Users\%UserName%\AppData\Local\Temp
|
|
|
| Desktop Folder |
C:\Users\%UserName%\Desktop
|
|
NTUSER.DAT
- Every user profile has an NTUSER.DAT file
- It is a registry file
- Updated by the OS once the user logs out
- Last written time can be used to pin point user last log out time
- Requires registry viewer to view the contents
Cookies
- Examiners can use cookie decoder to decode the cookie and examine the contents
- Cookie can be used for:
- Authentication
- Storing site preferences
- Shopping cart contents
- Identifier for a server-based session
- Index.dat
- file is a database file that contains the data about each cookie and pointers to the cookie file to the originating website name
- Contains dates and the cookie itself contains its own internal date
- Internal dates can show last modified by the website and its expiration date
Send To Folder
- Default selections include:
- Documents
- Desktop
- Mail Recipient
- Drives
- Applications may add additional options to this folder and users has the ability to create entries in this folder
Web Browsers
| Browser | Favorites Path | Bookmarks Path | History Path | Cookies Path | Additional Information |
|---|---|---|---|---|---|
| Internet Explorer | C:\Users\%UserName%\Favorites |
C:\Users\%UserName%\AppData\Local\Microsoft\Windows\History History.IE5 Low\History.IE5 |
C:\Users\%UserName%\AppData\Roaming\Microsoft\Windows\Cookies C:\Users\%UserName%\AppData\Roaming\Microsoft\Windows\Cookies\Low |
||
| Google Chrome | C:\Users\%UserName%\AppData\Local\Google\Chrome\User Data\Default\ |
C:\Users\%UserName%\AppData\Local\Google\Chrome\User Data\Default\ |
C:\Users\%UserName%\AppData\Local\Google\Chrome\User Data\Default\ |
Files use SQLite database format | |
| Mozilla Firefox | C:\Users\%UserName%\AppData\Roaming\mozilla\Firefox\Profiles\xx.default\places.sqlite |
C:\Users\%UserName%\AppData\Roaming\mozilla\Firefox\Profiles\xx.default\places.sqlite |
C:\Users\%UserName%\AppData\Roaming\mozilla\Firefox\Profiles\xx.default\places.sqlite |
Files use SQLite database format |
Online Communication Tools
| Application | History/Conversations Path |
|---|---|
| Skype | C:\Users\%UserName%\AppData\Roaming\Skype\<aliases>\main.db |
| MS Team | Office 365 Group Mailbox Conversation History\Team Chat Private Chats User's Mailbox\Conversation History\Team Chat |
Last update:
June 11, 2023
Created: June 11, 2023
Created: June 11, 2023