Deleted Files & File Knowledge—DFIR Workflow & Cheatsheet
Quick Reference: Investigation Priority Matrix
Priority
Artifact
Key Questions Answered
Data Retention
OS Version
Investigation Workflow
Phase 1: Deleted File Recovery (Critical Priority)
1.1 Recycle Bin Analysis
Phase 2: File Existence & Metadata (High Priority)
2.1 Windows Search Database (ESE Database)
2.2 Internet Explorer File History
Phase 3: File Access & User Knowledge (Medium Priority)
3.1 Recent Documents MRU (Most Recently Used)
3.2 WordWheelQuery (File Explorer Searches)
3.3 TypedPaths (Manually Entered Paths)
Phase 4: Visual Evidence (Medium Priority)
4.1 Thumbcache (Windows Vista+)
4.2 Thumbs.db (Legacy - Windows XP)
Advanced Investigation Techniques
SID to Username Mapping
Timeline Correlation Strategy
Anti-Forensics Detection
Network Share & USB Evidence
Investigation Checklists
Quick Triage Checklist
Deleted File Investigation
File Knowledge Investigation
Visual Evidence Recovery
Network & External Access
Essential DFIR Tools
Registry Analysis
Recycle Bin
Windows Search Database
Thumbnails
Comprehensive Suites
Timeline Analysis
Quick Command Reference
PowerShell Collection Script
Batch Forensic Parsing
SID Enumeration
File Path Variables
Common Forensic Scenarios
Scenario 1: Prove File Existed (Deleted, Not in Recycle Bin)
Scenario 2: User Searched for Sensitive Terms
Scenario 3: USB Drive File Access
Scenario 4: Network Share Access
Investigation Gotchas & Notes
Recycle Bin
Windows Search Database
Thumbcache
MRU Lists
IE File History
Best Practices
Evidence Preservation
Analysis Methodology
Reporting
PreviousBrowser Forensics – DFIR Workflow & CheatsheetNextUSB Device & External Storage - DFIR Workflow & Cheatsheet
Last updated
