Overview
Syllabus
Intro
Introducing: Matt Scheurer
Data Preservation Methodology
The Windows SRUM Database
Useful SRUM Data
Network Resource Usage
SRUM Database Conclusions
Web Browser Artifacts
Investigation Tooling
Artifact Sources
Memory Dumps
Example History Artifact Paths
History Parsed Example 4/4
Download Parsed Example 1/2
PowerShell Artifacts Collection
Objectives
Warning!
PowerShell Logging
PowerShell Version
PowerShell Pro Tip!
System Time
Hashing Files
Less Volatile Network Artifacts
Execution Policy Settings
Clipboard, Auto-runs, and Tasks
Host Details
The Open Files Conundrum
More PowerShell Tips & Tricks
Thank you for attending!