Skip to content

フォレンジックアーティファクトリファレンス

デジタルフォレンジックのアーティファクトについて、内容、保存場所、調査での活用方法を整理した実務向けカタログです。

35件のアーティファクトを掲載中です。

Windows

13 件のアーティファクト
レジストリ

Shell Bags

Windows Explorer view preferences recorded per-folder in UsrClass.dat. Shell Bags prove a user navigated to a folder, even after the folder or attached volume is long gone.

T1083
重大実行痕跡

Amcache.hve

Compatibility database introduced in Windows 8 that records every PE file executed on the system, including SHA-1 hash, full path, publisher, and first-seen timestamp.

T1204.002T1059
実行痕跡

UserAssist

Per-user registry key recording GUI-launched programs with ROT13-obfuscated paths, focus count, and last execution time — proving interactive user execution of a binary.

T1204.002
実行痕跡

MUICache

Per-user cache of application display names written the first time a binary runs. Every entry is evidence that the user ran that binary at least once.

T1204.002
重大実行痕跡

Prefetch Files

Windows Prefetch stores up to the last 8 execution times of a binary along with loaded DLLs and volume information — a foundational timeline artifact for Windows investigations.

T1204.002T1036
重大実行痕跡

Shimcache (AppCompatCache)

Application Compatibility Cache stores up to 1024 executed binary records with full path and last-modified timestamp. Persists even when a binary is deleted.

T1059T1204.002
実行痕跡

BAM / DAM

Background Activity Moderator and Desktop Activity Moderator record last-execution timestamps per user SID for every binary the system considers interactive.

T1204.002
ブラウザ

TypedURLs

Internet Explorer / Edge Legacy registry key storing the last 25 URLs a user typed manually into the address bar — stronger evidence than a general visit record.

T1071.001
システム

RecentDocs

Explorer tracks recently opened files per extension in HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs, including files on removed storage.

T1083
実行痕跡

AppCompatCache Flags

Application compatibility flags set per-binary by Windows and optionally by malware to modify how executables run. Layered onto Shimcache telemetry.

T1546.011
ネットワーク

WiFi Profile Registry

Windows stores every SSID a machine has connected to under HKLM, along with connection timestamps and MAC address of the AP — strong location evidence.

T1016
ネットワーク

Windows Bluetooth Pairings

Windows records paired Bluetooth devices under HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Devices, preserving MAC and name after unpairing.

T1011.001
重大ネットワーク

USB Device Connection History

Windows records every USB mass-storage device plugged in, keyed by vendor/product ID and serial number, with first- and last-connection timestamps.

T1052.001T1091

macOS

6 件のアーティファクト

iOS

4 件のアーティファクト

Android

4 件のアーティファクト

クロスプラットフォーム

3 件のアーティファクト

Linux

5 件のアーティファクト

証拠データを解析しますか?

unJaena AIはこのカタログ内の全アーティファクトと200件以上の追加項目を自動で解析します。

無料分析を開始