Forensic Integrations
Explore the Windows forensic artifacts TensorGuard collects and analyzes at fleet scale — $MFT, AmCache, SRUM, PowerShell history, Microsoft 365, and more.
AmCache
BAM/DAM
Event Logs
Jumplists
MFT
Microsoft 365
Network List
Prefetch
Profile Lists
PS History
RDP Client
Recent Lnks
Recycle Bin
Scheduled Tasks
Services
Shell Bags
ShimCache
Slack
SRUM
Startup Tasks
User MRU
UserAssist
USN Journal
Web Browser
AmCache
BAM/DAM
Event Logs
Jumplists
MFT
Microsoft 365
Network List
Prefetch
Profile Lists
PS History
RDP Client
Recent Lnks
Recycle Bin
Scheduled Tasks
Services
Shell Bags
ShimCache
Slack
SRUM
Startup Tasks
User MRU
UserAssist
USN Journal
Web Browser
Explore All Artifacts
Microsoft 365
All
A comprehensive suite of cloud logs capturing user authentication, email routing, and application permissions within the tenant.
About Microsoft 365Shell Bags
Windows
Remembers which folders a user has opened, creating a map of their navigation history.
About Shell BagsServices
Windows
The complete service and driver configuration database — binary paths, start types, and run-as accounts — where attackers hide persistence that starts with the OS.
About ServicesBAM/DAM
Windows
A Windows registry artifact that reliably tracks executed programs and links them directly to the specific user account that ran them.
About BAM/DAMWeb Browser
All
A detailed log of websites visited and files downloaded, showing a user's online activity.
About Web BrowserScheduled Tasks
Windows
A native Windows feature used to automate execution, frequently abused by adversaries for stealthy persistence and lateral movement.
About Scheduled TasksShimCache
Windows
A system compatibility record that serves as evidence of which programs have been executed.
About ShimCacheUser MRU
Windows
The registry's "Most Recently Used" lists — Run dialog commands, typed Explorer paths, and recently opened files — direct evidence of deliberate, interactive user action.
About User MRURecent Lnks
Windows
Automatically created shortcuts that show which files a user has recently opened or accessed.
About Recent LnksMFT
Windows
A master index of every file on the disk, including critical information about deleted files.
About MFTEvent Logs
Windows
The computer's diary, recording important system, security, and application events as they happen.
About Event LogsNetwork List
Windows
Every Wi-Fi and wired network a device has ever joined — SSIDs with first and last connection dates — a location and behavior history of the machine itself.
About Network ListRecycle Bin
Windows
A critical repository of deleted files and their metadata, revealing exactly what a user attempted to remove and when.
About Recycle BinStartup Tasks
Windows
A critical record of applications and services configured to execute automatically at boot or user logon, frequently abused by malware to maintain persistence.
About Startup TasksAmCache
Windows
Tracks programs that have run on a computer, providing a history of application usage.
About AmCacheSlack
All
A record of user messages and file transfers that provides evidence of conversations and insider threats.
About SlackSRUM
Windows
Details which applications used network data and CPU time, helping to track internet and program activity.
About SRUMJumplists
Windows
Reveals recently opened files, showing a history of a user's document and application access.
About JumpListsUserAssist
Windows
Tracks applications launched via the Windows graphical user interface, revealing specific user activity, run counts, and execution times.
About UserAssistPrefetch
Windows
A performance-enhancing artifact that provides definitive proof of application execution, run counts, and the specific files accessed during launch.
About PrefetchPS History
Windows
A command log that reveals specific, advanced actions performed by administrators or sophisticated users.
About PS HistoryUSN Journal
Windows
A hidden system log that records changes made to files and directories, revealing a timeline of file creation, modification, and deletion.
About USN JournalRDP Client
Windows
The client-side diary of every Remote Desktop session a user has initiated — servers, usernames, and settings, recorded in the user's own registry hive.
About RDP ClientProfile Lists
Windows
Identifies every user account that has logged into the computer and their associated profile folder.
About Profile ListsJoin the future of forensics.
Start with a flat-fee Compromise Assessment — fully credited toward a subscription.






