Windows Forensics

2 Results / Page 1 of 1

Background

todaySeptember 9, 2026

close

Computer Forensics + Digital Forensics Neerav Jindal

Amcache, Shimcache & UserAssist: Windows Forensic Artifacts

Windows computers leave behind many digital traces during normal use. These traces can help forensic investigators understand which applications existed on a system and identify evidence related to user activity. Among the most important Windows forensic artifacts are Amcache, Shimcache, and UserAssist. Each artifact records different information. Therefore, investigators must ...

todayJune 13, 2026

close

Data forensic + Blog + digital forensic + Cyber Forensic Harinandhan A S

Memory Forensics: Recovering Hidden Evidence from RAM

Introduction When investigating a cyber incident, many people focus on hard drives, mobile devices, or cloud storage. However, some of the most valuable digital evidence never gets written to disk. Instead, it exists temporarily in a computer’s Random Access Memory (RAM). This is where Memory Forensics becomes essential. Memory Forensics ...