Windows Artifact Database

Digital Forensics and Incident Response (DFIR) investigation scenerios often revolve around anwsering a specific question. As a result, SANS, the industry leader for Cyber Security training categorizes forensic artifacts by the specific questions that you're trying to anwser. I referenced SANS Windows Forensic Analysis poster to create this database and added some additional contextual information help jumpstart your analysis.