Windows forensic artefacts are one of the core evidence sources used in DFIR investigations, but investigations often fail not because analysts cannot extract artefacts, but because they over-interpret them. This article explains how to treat Windows artefacts as evidence, not indicators, and how to reason about them defensibly.
A practical SANS/GIAC certification roadmap for SOC analysts, incident responders, and DFIR practitioners choosing GSEC, GCIH, GCFE, GCFA, GRID, or SANS Work-Study.
It can be difficult when there are so many different roles and job titles and little standardisation. The requirements for a role can differ vastly depending on the hiring manager and the HR team (not to call anyone out, it's a fast moving field and it's hard to keep up). There's no shortage of advice like this; I realise of course that a quick Google search brings up a multitude of similar blogs, but if people are still asking 'where do I start,' at least having written this I have somewhere to point them for a quick rundown of my thoughts.
A DFIR guide to Windows persistence forensics, including services, scheduled tasks, Run keys, autoruns, and what persistence artefacts can and can't prove.
A practical breakdown of what actually changes between GCFE-level and GCFA-level work, including how investigative thinking, scope, and decision-making evolve in real-world DFIR.
Windows Shimcache and Amcache forensics guide explaining whether these artefacts prove program execution, what they can show, and how to corroborate execution claims.
Windows Prefetch forensics guide explaining whether Prefetch proves execution, what `.pf` files show, and how Digital Forensics and Incident Response (DFIR) analysts should corroborate Prefetch evidence.
This series is deliberately slow. It's trying to build an instinct, not a checklist.
In the first article, we framed Windows artefacts as partial, contextual evidence rather than deterministic indicators. In the ShellBags post, we applied that framing to a common mistake: treating shell navigation as proof of file access or intent. ShellBags are a record of what File Explorer remembers about where a user navigated and how those folders were rendered. That's valuable. It's also easy to over-interpret.
What actually changes when moving from SOC analyst to incident responder? A practical breakdown of skills, mindset, and decision-making in real-world DFIR roles.
ShellBags forensics guide explaining what Windows ShellBag artefacts record, what they prove about folder navigation, and why they do not prove file access or execution.