> For the complete documentation index, see [llms.txt](https://windows.dfirhandbook.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://windows.dfirhandbook.com/windows-artifacts/program-execution.md).

# Program Execution

- [Prefetch](https://windows.dfirhandbook.com/windows-artifacts/program-execution/prefetch.md)
- [Decoding Prefetch Files with Eric Zimmerman's PECmd Tool](https://windows.dfirhandbook.com/windows-artifacts/program-execution/prefetch/decoding-prefetch-files-with-eric-zimmermans-pecmd-tool.md)
- [BAM/DAM](https://windows.dfirhandbook.com/windows-artifacts/program-execution/bam-dam.md)
- [CapabilityAccessManager](https://windows.dfirhandbook.com/windows-artifacts/program-execution/capabilityaccessmanager.md)
- [UserAssist](https://windows.dfirhandbook.com/windows-artifacts/program-execution/userassist.md)
- [Last Visited MRU](https://windows.dfirhandbook.com/windows-artifacts/program-execution/last-visited-mru.md)
- [RunMRU](https://windows.dfirhandbook.com/windows-artifacts/program-execution/runmru.md)
- [MUI Cache](https://windows.dfirhandbook.com/windows-artifacts/program-execution/mui-cache.md)
- [ShimCache](https://windows.dfirhandbook.com/windows-artifacts/program-execution/shimcache.md)
- [Amcache](https://windows.dfirhandbook.com/windows-artifacts/program-execution/amcache.md)
- [Jump Lists](https://windows.dfirhandbook.com/windows-artifacts/program-execution/jump-lists.md)
