What is a .lnk file?
What is an important note about .lnk files?
Where are the most common locations to find .lnk files?
.lnk timestamps?
Tools for .lnk forensics?
Thumbnails
Volume ShadowCopy Service
Prefetch Files
Prefetch Content for Executables
Location of Prefetch Files
- .pf extension
Prefetch Registry Keys
ShimCache
Windows Registry
Registry Structure
Registry Root Keys
Common Hive Locations
HKLM
BCD
HARDWARE
SAM
SECURITY
SOFTWARE
SYSTEM
What does a Registry Key hold?