Skip to content

Artifacts parsed

TRACE’s user activity module reads these into one record shape and onto the timeline. Each record links to the file it came from.

Artifact What it tells you
Prefetch (XP to 11, LZXPRESS-compressed included) programs run, run counts, last run times
Amcache programs present and run, with hashes
Shimcache (AppCompatCache) programs seen by the compatibility layer
UserAssist, BAM programs run by each user
RunMRU, TypedPaths, WordWheelQuery Run box commands, Explorer paths typed, Explorer searches
ShellBags folders browsed, including on removed drives
LNK shortcuts, Jump Lists, RecentDocs, Office recent files files opened
USBSTOR, DeviceClasses, MountPoints2, setupapi logs USB devices: what, when first and last, which user
Event logs (EVTX, and XP .evt) logons and sessions, with service and machine accounts left out
PowerShell history and script-block logging (4104) commands typed and scripts run, blocks joined
SRUM application, network and energy use; connectivity
Windows Timeline (ActivitiesCache.db) activity history
WebCache, index.dat Internet Explorer and legacy Edge history and downloads
NetworkList, TimeZoneInformation, Uninstall, CurrentVersion networks joined, time zone, installed programs, Windows version
Recycle Bin ($I/$R, INFO2, deleted $I records) what was deleted, from where, when
Microsoft Defender MPLog, detection history, quarantine detections and quarantined files
thumbcache, Thumbs.db, Windows Search index, RDP bitmap cache pictures seen, including of files now gone
NTFS $MFT, $UsnJrnl, $I30 slack, $LogFile file events, timestomping, traces of deleted files