EC-Council Certified Ethical Hacker (CEH) v12System Hacking Phases and Attack TechniquesHard
A forensic investigator is examining a Windows server after a suspected compromise. They need to determine if any malicious executables were run and if their execution traces have been tampered with. Which of the following Windows artifacts would be MOST critical to examine for evidence of program execution, especially if log files were cleared?
- AThe Windows Event Logs (Security, System, Application)
- BThe Recycle Bin contents
- CPrefetch files (.pf) in C:\Windows\Prefetch
- DThe Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
Show answer & explanationAnswer & explanation
Correct answer: C. Prefetch files (.pf) in C:\Windows\Prefetch
Prefetch files (.pf) are highly valuable forensic artifacts on Windows. They record information about applications executed on the system, including their execution count and timestamps. Unlike event logs which can be cleared, prefetch files are harder for attackers to tamper with consistently and provide strong evidence of program execution, even for portable executables.
Why the other options are wrong
- A. While critical, the scenario implies logs *might* have been cleared, making prefetch files a more resilient source for execution evidence.
- B. Recycle Bin contents only show deleted files, not necessarily executed programs.
- D. This key shows installed services, not necessarily all executed programs.
Windows Prefetch Files
Files created by the Windows operating system to speed up application startup. They contain information about the executable, its run count, and the files/directories it accessed during the first 10 seconds of execution.
- Located in C:\Windows\Prefetch.
- Contain strong evidence of program execution.
- Difficult for attackers to completely eradicate without leaving traces.
Memory trick: To 'see' what 'ran' on Windows, 'prefetch' the execution data.