PHASE: Prefetch Files33% COMPLETION
Abort Mission
MODULE 05

Windows Forensics: Artifacts

Prefetch, Jump Lists, LNK files, and Shellbags.

Prefetch Files

Windows creates .pf files to speed up application loading.
Location: C:\Windows\Prefetch

Forensic Value

Proves a program was executed, even if deleted. Contains last run time and run count.