Skip to content

Latest commit

 

History

History
35 lines (28 loc) · 431 Bytes

files.md

File metadata and controls

35 lines (28 loc) · 431 Bytes

Typically C:\Windows

%SYSTEMROOT%

DNS entries

%SYSTEMROOT%\System32\drivers\etc\hosts

User & password hashes

%SYSTEMROOT%\system32\config\SAM

Backup of SAM

%SYSTEMROOT%\repair\SAM

Backup of SAM

%SYSTEMROOT%\System32\config\RegBack\SAM

Application Log

%WINDIR%\system32\config\AppEvent.Evt

Security Log

%WINDIR%\system32\config\SecEvent.Evt