Windows Disk
Last updated
Was this helpful?
Last updated
Was this helpful?
The Windows System Resource Usage Monitor (SRUM) is a tool designed to track system resource usage comprehensively. It records details such as application resource consumption, energy usage, network connectivity, data usage, and Windows push notifications.
The SRUM database maintains a log of program executions, power consumption patterns, network activities, and various other system interactions, offering a valuable resource for retrieving information even if the original source data has been deleted.
Location: C:\Windows\System32\SRU\SRUDB.dat
SRUM Application Resource Usage (Most value)
SRUM Network Usage (Most value)
SRUM Network Connections
SRUM Energy Usage
SRUM Push Notification Data
SRUM Energy Usage (Long Term)
The Jump Lists feature is designed to give users quick access to recently opened application files and frequently used tasks.
Reference: USB Forensic
The recycle bin serves as a temporary storage location for items deleted by the user.
$I files store metadata, including the file path, size, and deletion timestamp. Each $I file is paired with a $R file, which holds the actual content of the deleted file, as long as the item has not been permanently removed.
The Windows Search service functions as an internal dictionary, operating in the background to collect and index the system's content. The service "provides content indexing, property caching, and search results for files, e-mail, and other content".
When a user searches for a document, image, or any other file type, the query is directed to the Windows Search Index database, rather than performing a real-time search on the system.
Our primary focus is on the File_Report and Internet_History_Report data.
When a user connects to another system via RDP, small bitmap images are stored in their RDP profile files. This allows the system to quickly fetch or retrieve these images for reuse during the session.
C:\Users\<username>\AppData\Local\Microsoft\Terminal Server Client\Cache
In RDP lateral movement investigations, RDP bitmap cache files are key evidence.
ThumbCache is a feature that stores thumbnail images of files for Windows Explorer's thumbnail view. These images, representing the contents of files, are stored in a centralized Thumbnail Cache file.
These files are named Thumcache_xxx.db and iconcache_xxxx.db, where "xxx" represents the bits, pixel, or resolution value.
Location: C:$Recycle.Bin{SID}$I######
Location : C:\%USERPROFILE%\ProgramData\Microsoft\Search\Data\Applications\Windows\Windows.edb
Location:
Location: C:\Users\[Username]\AppData\Local\Microsoft\Windows\Explorer
This knowledge has been compiled from resources provided by .