> For the complete documentation index, see [llms.txt](https://windows.dfirhandbook.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://windows.dfirhandbook.com/windows-artifacts.md).

# Windows Artifacts

- [Windows Quick Tips](https://windows.dfirhandbook.com/windows-artifacts/windows-quick-tips.md)
- [Windows Command Line](https://windows.dfirhandbook.com/windows-artifacts/windows-quick-tips/windows-command-line.md)
- [Workstation File/Folder Locations](https://windows.dfirhandbook.com/windows-artifacts/windows-quick-tips/workstation-file-folder-locations.md)
- [Server File/Folder Locations](https://windows.dfirhandbook.com/windows-artifacts/windows-quick-tips/server-file-folder-locations.md)
- [Account Usage](https://windows.dfirhandbook.com/windows-artifacts/account-usage.md)
- [Authentications SAM Artifacts](https://windows.dfirhandbook.com/windows-artifacts/account-usage/authentications-sam-artifacts.md)
- [Last Login](https://windows.dfirhandbook.com/windows-artifacts/account-usage/authentications-sam-artifacts/last-login.md)
- [Last Failed Login](https://windows.dfirhandbook.com/windows-artifacts/account-usage/authentications-sam-artifacts/last-failed-login.md)
- [Last Password Change](https://windows.dfirhandbook.com/windows-artifacts/account-usage/authentications-sam-artifacts/last-password-change.md)
- [Authentications (Windows Event Log)](https://windows.dfirhandbook.com/windows-artifacts/account-usage/authentications-windows-event-log.md)
- [Logon ID](https://windows.dfirhandbook.com/windows-artifacts/account-usage/authentications-windows-event-log/logon-id.md)
- [Group Membership](https://windows.dfirhandbook.com/windows-artifacts/account-usage/group-membership.md)
- [Event ID: 4798](https://windows.dfirhandbook.com/windows-artifacts/account-usage/group-membership/event-id-4798.md)
- [Event ID: 4799](https://windows.dfirhandbook.com/windows-artifacts/account-usage/group-membership/event-id-4799.md)
- [RDP](https://windows.dfirhandbook.com/windows-artifacts/account-usage/rdp.md)
- [Source System Artifacts - Quick Reference](https://windows.dfirhandbook.com/windows-artifacts/account-usage/rdp/source-system-artifacts-quick-reference.md)
- [Destination System Artifacts - Quick Reference](https://windows.dfirhandbook.com/windows-artifacts/account-usage/rdp/destination-system-artifacts-quick-reference.md)
- [SSH](https://windows.dfirhandbook.com/windows-artifacts/account-usage/ssh.md)
- [Rouge Local Accounts](https://windows.dfirhandbook.com/windows-artifacts/account-usage/rouge-local-accounts.md)
- [CrowdStrike Searches](https://windows.dfirhandbook.com/windows-artifacts/account-usage/crowdstrike-searches.md)
- [Event Name - UserLogon](https://windows.dfirhandbook.com/windows-artifacts/account-usage/crowdstrike-searches/event-name-userlogon.md)
- [Event Name - UserLogonFailed](https://windows.dfirhandbook.com/windows-artifacts/account-usage/crowdstrike-searches/event-name-userlogonfailed.md): UserLogonFailed2 will aggregate data from Falcon and Windows ETW when available (assuming you're using a more modern Windows operating system) and UserLongFailed will rely exclusively on Falcon data.
- [Event Name - UserLogonFailed2](https://windows.dfirhandbook.com/windows-artifacts/account-usage/crowdstrike-searches/event-name-userlogonfailed2.md): UserLogonFailed2 will aggregate data from Falcon and Windows ETW when available (assuming you're using a more modern Windows operating system) and UserLongFailed will rely exclusively on Falcon data.
- [Event Name - SsoApplicationAccess](https://windows.dfirhandbook.com/windows-artifacts/account-usage/crowdstrike-searches/event-name-ssoapplicationaccess.md)
- [Browser Usage](https://windows.dfirhandbook.com/windows-artifacts/browser-usage.md)
- [History & Downloads](https://windows.dfirhandbook.com/windows-artifacts/browser-usage/history-and-downloads.md)
- [Viewing History Files - DB Browser](https://windows.dfirhandbook.com/windows-artifacts/browser-usage/history-and-downloads/viewing-history-files-db-browser.md)
- [Transition Types](https://windows.dfirhandbook.com/windows-artifacts/browser-usage/history-and-downloads/transition-types.md)
- [Auto-Complete Data](https://windows.dfirhandbook.com/windows-artifacts/browser-usage/auto-complete-data.md)
- [Bookmarks](https://windows.dfirhandbook.com/windows-artifacts/browser-usage/bookmarks.md)
- [Browser Preferences](https://windows.dfirhandbook.com/windows-artifacts/browser-usage/browser-preferences.md)
- [Cache](https://windows.dfirhandbook.com/windows-artifacts/browser-usage/cache.md)
- [Cookies](https://windows.dfirhandbook.com/windows-artifacts/browser-usage/cookies.md)
- [Extensions](https://windows.dfirhandbook.com/windows-artifacts/browser-usage/extensions.md)
- [Super Cookies (HTML5 Web Storage)](https://windows.dfirhandbook.com/windows-artifacts/browser-usage/super-cookies-html5-web-storage.md)
- [Media History](https://windows.dfirhandbook.com/windows-artifacts/browser-usage/media-history.md)
- [Private Browsing](https://windows.dfirhandbook.com/windows-artifacts/browser-usage/private-browsing.md)
- [Session Restore](https://windows.dfirhandbook.com/windows-artifacts/browser-usage/session-restore.md)
- [Stored Credentials](https://windows.dfirhandbook.com/windows-artifacts/browser-usage/stored-credentials.md)
- [Suggested/Frequent Sites](https://windows.dfirhandbook.com/windows-artifacts/browser-usage/suggested-frequent-sites.md)
- [DB Browser Queries](https://windows.dfirhandbook.com/windows-artifacts/browser-usage/db-browser-queries.md)
- [Firefox](https://windows.dfirhandbook.com/windows-artifacts/browser-usage/db-browser-queries/firefox.md)
- [Chrome](https://windows.dfirhandbook.com/windows-artifacts/browser-usage/db-browser-queries/chrome.md)
- [Media History](https://windows.dfirhandbook.com/windows-artifacts/browser-usage/db-browser-queries/media-history.md)
- [PowerShell Scripts](https://windows.dfirhandbook.com/windows-artifacts/browser-usage/powershell-scripts.md)
- [Browser Extension Finder](https://windows.dfirhandbook.com/windows-artifacts/browser-usage/powershell-scripts/browser-extension-finder.md)
- [Browser History Finder](https://windows.dfirhandbook.com/windows-artifacts/browser-usage/powershell-scripts/browser-history-finder.md)
- [Processes](https://windows.dfirhandbook.com/windows-artifacts/processes.md)
- [at.exe](https://windows.dfirhandbook.com/windows-artifacts/processes/at.exe.md): Superseded by schtasks.exe in later versions of Windows, understanding at.exe remains relevant for analyzing older systems.
- [explorer.exe](https://windows.dfirhandbook.com/windows-artifacts/processes/explorer.exe.md)
- [lsass.exe](https://windows.dfirhandbook.com/windows-artifacts/processes/lsass.exe.md)
- [lsaiso.exe](https://windows.dfirhandbook.com/windows-artifacts/processes/lsaiso.exe.md)
- [PuTTy.exe](https://windows.dfirhandbook.com/windows-artifacts/processes/putty.exe.md)
- [X11 Forwarding](https://windows.dfirhandbook.com/windows-artifacts/processes/putty.exe/x11-forwarding.md)
- [runtimebroker.exe](https://windows.dfirhandbook.com/windows-artifacts/processes/runtimebroker.exe.md)
- [services.exe](https://windows.dfirhandbook.com/windows-artifacts/processes/services.exe.md)
- [smss.exe](https://windows.dfirhandbook.com/windows-artifacts/processes/smss.exe.md)
- [System](https://windows.dfirhandbook.com/windows-artifacts/processes/system.md)
- [svchost.exe](https://windows.dfirhandbook.com/windows-artifacts/processes/svchost.exe.md)
- [Services](https://windows.dfirhandbook.com/windows-artifacts/processes/svchost.exe/services.md): Common services seen running under svchost.exe
- [winlogon.exe](https://windows.dfirhandbook.com/windows-artifacts/processes/winlogon.exe.md)
- [wininit.exe](https://windows.dfirhandbook.com/windows-artifacts/processes/wininit.exe.md)
- [Cloud Storage](https://windows.dfirhandbook.com/windows-artifacts/cloud-storage.md)
- [Deleted File or File Knowledge](https://windows.dfirhandbook.com/windows-artifacts/deleted-file-or-file-knowledge.md)
- [WordWheelQuery (Win 7+)](https://windows.dfirhandbook.com/windows-artifacts/deleted-file-or-file-knowledge/wordwheelquery-win-7+.md)
- [ACMRU (Win XP)](https://windows.dfirhandbook.com/windows-artifacts/deleted-file-or-file-knowledge/acmru-win-xp.md)
- [Internet Explorer file:///](https://windows.dfirhandbook.com/windows-artifacts/deleted-file-or-file-knowledge/internet-explorer-file.md)
- [Last Visited MRU](https://windows.dfirhandbook.com/windows-artifacts/deleted-file-or-file-knowledge/last-visited-mru.md)
- [Thumbs.db (Win XP)](https://windows.dfirhandbook.com/windows-artifacts/deleted-file-or-file-knowledge/thumbs.db-win-xp.md)
- [Thumbcache](https://windows.dfirhandbook.com/windows-artifacts/deleted-file-or-file-knowledge/thumbcache.md)
- [Recycle Bin](https://windows.dfirhandbook.com/windows-artifacts/deleted-file-or-file-knowledge/recycle-bin.md)
- [User Typed Paths](https://windows.dfirhandbook.com/windows-artifacts/deleted-file-or-file-knowledge/user-typed-paths.md)
- [Windows Search Database](https://windows.dfirhandbook.com/windows-artifacts/deleted-file-or-file-knowledge/windows-search-database.md)
- [File Download](https://windows.dfirhandbook.com/windows-artifacts/file-download.md)
- [Zone.Identifier](https://windows.dfirhandbook.com/windows-artifacts/file-download/zone.identifier.md)
- [Open/Save Most Recently Used (MRU)](https://windows.dfirhandbook.com/windows-artifacts/file-download/open-save-most-recently-used-mru.md)
- [Email](https://windows.dfirhandbook.com/windows-artifacts/file-download/email.md)
- [Drive By Downloads](https://windows.dfirhandbook.com/windows-artifacts/file-download/drive-by-downloads.md)
- [Malvertising](https://windows.dfirhandbook.com/windows-artifacts/file-download/drive-by-downloads/malvertising.md)
- [Web Browsing](https://windows.dfirhandbook.com/windows-artifacts/file-download/web-browsing.md): Some MacOS included in here as well
- [Cache Files](https://windows.dfirhandbook.com/windows-artifacts/file-download/web-browsing/cache-files.md)
- [CrowdStrike Searches](https://windows.dfirhandbook.com/windows-artifacts/file-download/crowdstrike-searches.md)
- [MoTW](https://windows.dfirhandbook.com/windows-artifacts/file-download/crowdstrike-searches/motw.md)
- [Folder/File Opening/Creation](https://windows.dfirhandbook.com/windows-artifacts/folder-file-opening-creation.md)
- [Recent Files](https://windows.dfirhandbook.com/windows-artifacts/folder-file-opening-creation/recent-files.md)
- [Office Recent Files](https://windows.dfirhandbook.com/windows-artifacts/folder-file-opening-creation/office-recent-files.md)
- [Shell Bags](https://windows.dfirhandbook.com/windows-artifacts/folder-file-opening-creation/shell-bags.md)
- [.lnk Files](https://windows.dfirhandbook.com/windows-artifacts/folder-file-opening-creation/.lnk-files.md)
- [Jump Lists](https://windows.dfirhandbook.com/windows-artifacts/folder-file-opening-creation/jump-lists.md)
- [AppIDs](https://windows.dfirhandbook.com/windows-artifacts/folder-file-opening-creation/jump-lists/appids.md): https://github.com/EricZimmerman/JumpList/blob/master/JumpList/Resources/AppIDs.txt
- [Prefetch](https://windows.dfirhandbook.com/windows-artifacts/folder-file-opening-creation/prefetch.md)
- [Index.dat file://](https://windows.dfirhandbook.com/windows-artifacts/folder-file-opening-creation/index.dat-file.md)
- [PowerShell Scripts](https://windows.dfirhandbook.com/windows-artifacts/folder-file-opening-creation/powershell-scripts.md)
- [.lnk Files](https://windows.dfirhandbook.com/windows-artifacts/folder-file-opening-creation/powershell-scripts/.lnk-files.md)
- [PCA (Program Compatibility Assistant)](https://windows.dfirhandbook.com/windows-artifacts/folder-file-opening-creation/pca-program-compatibility-assistant.md)
- [Persistence](https://windows.dfirhandbook.com/windows-artifacts/persistence.md)
- [Registry](https://windows.dfirhandbook.com/windows-artifacts/persistence/registry.md)
- [NTUSER.DAT & HKU\SID](https://windows.dfirhandbook.com/windows-artifacts/persistence/registry/ntuser.dat-and-hku-sid.md)
- [Run and Run Once](https://windows.dfirhandbook.com/windows-artifacts/persistence/registry/run-and-run-once.md)
- [Shell Folders and UserInit Key](https://windows.dfirhandbook.com/windows-artifacts/persistence/registry/shell-folders-and-userinit-key.md): Registry keys like Shell Folders and UserInit are integral to Windows operating systems, impacting user environments and the login process
- [Services](https://windows.dfirhandbook.com/windows-artifacts/persistence/registry/services.md)
- [Logon Scripts](https://windows.dfirhandbook.com/windows-artifacts/persistence/registry/logon-scripts.md): Logon scripts offer a way for administrators to automate tasks that should occur each time a user logs on to a Windows system.
- [Office Add-ins](https://windows.dfirhandbook.com/windows-artifacts/persistence/registry/office-add-ins.md): Office Add-ins provide enhanced functionality and customization for Microsoft Office applications, enabling users to tailor their experience with additional features.
- [Winlogon Shell](https://windows.dfirhandbook.com/windows-artifacts/persistence/registry/winlogon-shell.md): his key's default and legitimate value is meant to launch the Windows Explorer, providing the standard desktop environment.
- [Image File Execution Options (IFEO)](https://windows.dfirhandbook.com/windows-artifacts/persistence/registry/image-file-execution-options-ifeo.md): IFEO allows for the configuration of certain behaviors when specified executables are launched, including attaching a debugger or modifying certain execution parameters.
- [AppInit\_DLLs](https://windows.dfirhandbook.com/windows-artifacts/persistence/registry/appinit_dlls.md): The AppInit\_DLLs registry key provides a mechanism for specifying one or more DLLs to be loaded into all processes that use the User32.dll.
- [Scheduled Tasks](https://windows.dfirhandbook.com/windows-artifacts/persistence/registry/scheduled-tasks.md)
- [Scheduled Tasks](https://windows.dfirhandbook.com/windows-artifacts/persistence/scheduled-tasks.md)
- [Scheduled Task Destination System Artifacts](https://windows.dfirhandbook.com/windows-artifacts/persistence/scheduled-tasks/scheduled-task-destination-system-artifacts.md)
- [Scheduled Task Source System Artifacts](https://windows.dfirhandbook.com/windows-artifacts/persistence/scheduled-tasks/scheduled-task-source-system-artifacts.md)
- [Startup](https://windows.dfirhandbook.com/windows-artifacts/persistence/startup.md)
- [Tool: AutoRuns](https://windows.dfirhandbook.com/windows-artifacts/persistence/tool-autoruns.md)
- [Accounts](https://windows.dfirhandbook.com/windows-artifacts/persistence/accounts.md)
- [WMI Event Consumers](https://windows.dfirhandbook.com/windows-artifacts/persistence/wmi-event-consumers.md)
- [WMI: Source System Artifacts](https://windows.dfirhandbook.com/windows-artifacts/persistence/wmi-event-consumers/wmi-source-system-artifacts.md)
- [WMI: Destination System Artifacts](https://windows.dfirhandbook.com/windows-artifacts/persistence/wmi-event-consumers/wmi-destination-system-artifacts.md)
- [WMI: PowerShell Analysis](https://windows.dfirhandbook.com/windows-artifacts/persistence/wmi-event-consumers/wmi-powershell-analysis.md)
- [PowerShell Scripts](https://windows.dfirhandbook.com/windows-artifacts/persistence/powershell-scripts.md)
- [Startup Programs](https://windows.dfirhandbook.com/windows-artifacts/persistence/powershell-scripts/startup-programs.md)
- [CrowdStrike Searches](https://windows.dfirhandbook.com/windows-artifacts/persistence/crowdstrike-searches.md)
- [Files Written to Startup Folder](https://windows.dfirhandbook.com/windows-artifacts/persistence/crowdstrike-searches/files-written-to-startup-folder.md)
- [Files Written to Startup Folder from the Internet](https://windows.dfirhandbook.com/windows-artifacts/persistence/crowdstrike-searches/files-written-to-startup-folder-from-the-internet.md)
- [Local Account Creation/Deletion](https://windows.dfirhandbook.com/windows-artifacts/persistence/crowdstrike-searches/local-account-creation-deletion.md)
- [Azure Account Creation/Deletion](https://windows.dfirhandbook.com/windows-artifacts/persistence/crowdstrike-searches/azure-account-creation-deletion.md)
- [Scheduled Tasks](https://windows.dfirhandbook.com/windows-artifacts/persistence/crowdstrike-searches/scheduled-tasks.md)
- [Physical Location](https://windows.dfirhandbook.com/windows-artifacts/physical-location.md)
- [Time zone](https://windows.dfirhandbook.com/windows-artifacts/physical-location/time-zone.md)
- [Wireless SSID](https://windows.dfirhandbook.com/windows-artifacts/physical-location/wireless-ssid.md)
- [Network History (Vista/Win7–11)](https://windows.dfirhandbook.com/windows-artifacts/physical-location/network-history-vista-win7-11.md)
- [Cookies](https://windows.dfirhandbook.com/windows-artifacts/physical-location/cookies.md)
- [Browser Search Terms](https://windows.dfirhandbook.com/windows-artifacts/physical-location/browser-search-terms.md)
- [Program Execution](https://windows.dfirhandbook.com/windows-artifacts/program-execution.md)
- [Prefetch](https://windows.dfirhandbook.com/windows-artifacts/program-execution/prefetch.md)
- [Decoding Prefetch Files with Eric Zimmerman's PECmd Tool](https://windows.dfirhandbook.com/windows-artifacts/program-execution/prefetch/decoding-prefetch-files-with-eric-zimmermans-pecmd-tool.md)
- [BAM/DAM](https://windows.dfirhandbook.com/windows-artifacts/program-execution/bam-dam.md)
- [CapabilityAccessManager](https://windows.dfirhandbook.com/windows-artifacts/program-execution/capabilityaccessmanager.md)
- [UserAssist](https://windows.dfirhandbook.com/windows-artifacts/program-execution/userassist.md)
- [Last Visited MRU](https://windows.dfirhandbook.com/windows-artifacts/program-execution/last-visited-mru.md)
- [RunMRU](https://windows.dfirhandbook.com/windows-artifacts/program-execution/runmru.md)
- [MUI Cache](https://windows.dfirhandbook.com/windows-artifacts/program-execution/mui-cache.md)
- [ShimCache](https://windows.dfirhandbook.com/windows-artifacts/program-execution/shimcache.md)
- [Amcache](https://windows.dfirhandbook.com/windows-artifacts/program-execution/amcache.md)
- [Jump Lists](https://windows.dfirhandbook.com/windows-artifacts/program-execution/jump-lists.md)
- [Shadow Copies](https://windows.dfirhandbook.com/windows-artifacts/shadow-copies.md)
- [VSC Permissions](https://windows.dfirhandbook.com/windows-artifacts/shadow-copies/vsc-permissions.md)
- [Event ID 8193: Volume Shadow Copy Service Error](https://windows.dfirhandbook.com/windows-artifacts/shadow-copies/event-id-8193-volume-shadow-copy-service-error.md)
- [USB Usage](https://windows.dfirhandbook.com/windows-artifacts/usb-usage.md)
- [Key Identification](https://windows.dfirhandbook.com/windows-artifacts/usb-usage/key-identification.md)
- [Drive Letter and Volume Name](https://windows.dfirhandbook.com/windows-artifacts/usb-usage/drive-letter-and-volume-name.md)
- [Connection Timestamps](https://windows.dfirhandbook.com/windows-artifacts/usb-usage/connection-timestamps.md)
- [User](https://windows.dfirhandbook.com/windows-artifacts/usb-usage/user.md)
- [Volume Name](https://windows.dfirhandbook.com/windows-artifacts/usb-usage/volume-name.md)
- [Plug & Play Event Log](https://windows.dfirhandbook.com/windows-artifacts/usb-usage/plug-and-play-event-log.md)
- [Windows Services](https://windows.dfirhandbook.com/windows-artifacts/windows-services.md)
- [DoSvc (Delivery Optimization)](https://windows.dfirhandbook.com/windows-artifacts/windows-services/dosvc-delivery-optimization.md)
- [System Information](https://windows.dfirhandbook.com/windows-artifacts/system-information.md)
- [Event IDs](https://windows.dfirhandbook.com/windows-artifacts/event-ids.md)
- [Security](https://windows.dfirhandbook.com/windows-artifacts/event-ids/security.md)
- [Authentication / Account](https://windows.dfirhandbook.com/windows-artifacts/event-ids/security/authentication-account.md)
- [4624 - Authentication Success](https://windows.dfirhandbook.com/windows-artifacts/event-ids/security/authentication-account/4624-authentication-success.md): https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4624
- [Logon Types](https://windows.dfirhandbook.com/windows-artifacts/event-ids/security/authentication-account/4624-authentication-success/logon-types.md)
- [4625 - Authentication Failure](https://windows.dfirhandbook.com/windows-artifacts/event-ids/security/authentication-account/4625-authentication-failure.md): https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4625
- [SubStatus Codes](https://windows.dfirhandbook.com/windows-artifacts/event-ids/security/authentication-account/4625-authentication-failure/substatus-codes.md)
- [4634 - Account Logoff](https://windows.dfirhandbook.com/windows-artifacts/event-ids/security/authentication-account/4634-account-logoff.md): https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4634
- [4648 - Explicit Credentials Success](https://windows.dfirhandbook.com/windows-artifacts/event-ids/security/authentication-account/4648-explicit-credentials-success.md): https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4648
- [4672 - Special Privileges](https://windows.dfirhandbook.com/windows-artifacts/event-ids/security/authentication-account/4672-special-privileges.md): https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4672
- [4720 - Account Creation](https://windows.dfirhandbook.com/windows-artifacts/event-ids/security/authentication-account/4720-account-creation.md): https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4720
- [4722 - Account Enabled](https://windows.dfirhandbook.com/windows-artifacts/event-ids/security/authentication-account/4722-account-enabled.md): https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4722
- [4732 - Addition to Local Group](https://windows.dfirhandbook.com/windows-artifacts/event-ids/security/authentication-account/4732-addition-to-local-group.md): https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4732
- [4738 - Account Changed](https://windows.dfirhandbook.com/windows-artifacts/event-ids/security/authentication-account/4738-account-changed.md): https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4738
- [4776 - Kerberos Authentication Attempt](https://windows.dfirhandbook.com/windows-artifacts/event-ids/security/authentication-account/4776-kerberos-authentication-attempt.md): https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4776
- [Substatus Codes](https://windows.dfirhandbook.com/windows-artifacts/event-ids/security/authentication-account/4776-kerberos-authentication-attempt/substatus-codes.md)
- [4771 - Kerberos Failure](https://windows.dfirhandbook.com/windows-artifacts/event-ids/security/authentication-account/4771-kerberos-failure.md): https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4771
- [4768](https://windows.dfirhandbook.com/windows-artifacts/event-ids/security/authentication-account/4768.md)
- [File System](https://windows.dfirhandbook.com/windows-artifacts/event-ids/security/file-system.md)
- [1006](https://windows.dfirhandbook.com/windows-artifacts/event-ids/security/file-system/1006.md)
- [4688 - Process Created](https://windows.dfirhandbook.com/windows-artifacts/event-ids/security/file-system/4688-process-created.md): https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4688
- [4663](https://windows.dfirhandbook.com/windows-artifacts/event-ids/security/file-system/4663.md)
- [4656](https://windows.dfirhandbook.com/windows-artifacts/event-ids/security/file-system/4656.md)
- [6416](https://windows.dfirhandbook.com/windows-artifacts/event-ids/security/file-system/6416.md)
- [20001](https://windows.dfirhandbook.com/windows-artifacts/event-ids/security/file-system/20001.md)
- [20003](https://windows.dfirhandbook.com/windows-artifacts/event-ids/security/file-system/20003.md)
