GCFA › Windows Artifact Analysis
This domain covers forensic examination of NTFS metadata, registry-backed execution artifacts, and shell item databases on Windows hosts. GCFA tests whether you can interpret $MFT records, $STANDARD_INFORMATION versus $FILE_NAME timestamps, ShimCache/AmCache entries, UserAssist, and Jump Lists to reconstruct file creation, execution, and user activity from an acquired image.
GCFA Windows Artifact Analysis — All 61 Questions
Every question in this domain with answers and detailed explanations.