Certified: SANS GIAC GSEC Audio Course
Episode 34 — Windows Investigation: Common Artifacts
22 Oct 2025
When incidents occur, the clues often hide in plain sight across the Windows operating system. This episode guides you through where to look and what to look for when conducting basic investigations. You’ll learn how timestamps, registry hives, and prefetch files reveal patterns of execution, installation, and persistence. We also discuss browser histories, jump lists, and temporary files as evidence sources that confirm user actions and system behavior. These artifacts aren’t random—they form a timeline that investigators use to reconstruct activity and validate hypotheses.Listeners will also discover how built-in tools like Event Viewer, dir /t, and the Windows Timeline feature complement third-party forensic utilities. We explain how volatile data like running processes, network connections, and system logs should be preserved quickly before being overwritten. The episode emphasizes exam-relevant distinctions between volatile and persistent evidence, and how to interpret forensic findings without overreach. By understanding what artifacts reveal and how they relate, you’ll be ready to analyze both test questions and real-world investigations with precision. Produced by BareMetalCyber.com, where you’ll find more cyber audio courses, books, and information to strengthen your educational path. Also, if you want to stay up to date with the latest news, visit DailyCyber.News for a newsletter you can use, and a daily podcast you can commute with.
No persons identified in this episode.
This episode hasn't been transcribed yet
Help us prioritize this episode for transcription by upvoting it.
Popular episodes get transcribed faster
Other recent transcribed episodes
Transcribed and ready to explore now
3ª PARTE | 17 DIC 2025 | EL PARTIDAZO DE COPE
01 Jan 1970
El Partidazo de COPE
Buchladen: Tipps für Weihnachten
20 Dec 2025
eat.READ.sleep. Bücher für dich
BOJ alza 25pb decennale sopra 2%, Oracle vola con accordo Tik Tok, 90 mld eurobond per Ucraina | Morning Finance
19 Dec 2025
Black Box - La scatola nera della finanza
365. The BEST advice for managing ADHD in your 20s ft. Chris Wang
19 Dec 2025
The Psychology of your 20s
LVST 19 de diciembre de 2025
19 Dec 2025
La Venganza Será Terrible (oficial)
Cuando la Ciencia Ficción Explicó el Mundo que Hoy Vivimos
19 Dec 2025
El Podcast de Marc Vidal