PHASE: Prefetch Files33% COMPLETION
MODULE 05
Windows Forensics: Artifacts
Prefetch, Jump Lists, LNK files, and Shellbags.
Prefetch Files
Windows creates .pf files to speed up application loading.
Location: C:\Windows\Prefetch
Forensic Value
Proves a program was executed, even if deleted. Contains last run time and run count.