Windows Forensics
System Information
IP Address & MAC Address
# Look@LAN is a network monitoring tool. So if the system uses the tool, we can retrieve the information of the network.
# LANIP -> IP address
# LANNIC -> MAC address
c:\Program Files (x86)\Look@LAN\irunin.iniNetwork Cards
c:\ProgramData\Microsoft\DiagnosticLogCSP\Collectors\DiagnosticLogCSP_Collector_DeviceProvisioning_2023_1_2_3_45_67.etlPowerShell History
c:\Users\<username>\AppData\Roaming\Microsoft\Windows\PowerShell\PSReadline\ConsoleHost_history.txtMalware History
Event Logs
Event Viewer
PowerShell
Processes
Process Monitor
Registry Hives
Registry Editor
File Locations
Acquire Registry Data
Gather Information From Registry Hives
OS Version
Current Control Set
Computer Name
Time Zone
Network
SAM Hive & User Information
Recent Files
Microsoft Office Recent Files
ShellBags
ShimCache
AmCache
BAM/DAM
UserAssist
Devices
References
Last updated