Forensic Integrations

Explore the Windows forensic artifacts TensorGuard collects and analyzes at fleet scale — $MFT, AmCache, SRUM, PowerShell history, Microsoft 365, and more.

AmCache

AmCache

BAM/DAM

BAM/DAM

Event Logs

Event Logs

Jumplists

Jumplists

MFT

MFT

Microsoft 365

Microsoft 365

Network List

Network List

Prefetch

Prefetch

Profile Lists

Profile Lists

PS History

PS History

RDP Client

RDP Client

Recent Lnks

Recent Lnks

Recycle Bin

Recycle Bin

Scheduled Tasks

Scheduled Tasks

Services

Services

Shell Bags

Shell Bags

ShimCache

ShimCache

Slack

Slack

SRUM

SRUM

Startup Tasks

Startup Tasks

User MRU

User MRU

UserAssist

UserAssist

USN Journal

USN Journal

Web Browser

Web Browser

AmCache

AmCache

BAM/DAM

BAM/DAM

Event Logs

Event Logs

Jumplists

Jumplists

MFT

MFT

Microsoft 365

Microsoft 365

Network List

Network List

Prefetch

Prefetch

Profile Lists

Profile Lists

PS History

PS History

RDP Client

RDP Client

Recent Lnks

Recent Lnks

Recycle Bin

Recycle Bin

Scheduled Tasks

Scheduled Tasks

Services

Services

Shell Bags

Shell Bags

ShimCache

ShimCache

Slack

Slack

SRUM

SRUM

Startup Tasks

Startup Tasks

User MRU

User MRU

UserAssist

UserAssist

USN Journal

USN Journal

Web Browser

Web Browser

Explore All Artifacts

Microsoft 365

Microsoft 365

All

A comprehensive suite of cloud logs capturing user authentication, email routing, and application permissions within the tenant.

About Microsoft 365
Shell Bags

Shell Bags

Windows

Remembers which folders a user has opened, creating a map of their navigation history.

About Shell Bags
Services

Services

Windows

The complete service and driver configuration database — binary paths, start types, and run-as accounts — where attackers hide persistence that starts with the OS.

About Services
BAM/DAM

BAM/DAM

Windows

A Windows registry artifact that reliably tracks executed programs and links them directly to the specific user account that ran them.

About BAM/DAM
Web Browser

Web Browser

All

A detailed log of websites visited and files downloaded, showing a user's online activity.

About Web Browser
Scheduled Tasks

Scheduled Tasks

Windows

A native Windows feature used to automate execution, frequently abused by adversaries for stealthy persistence and lateral movement.

About Scheduled Tasks
ShimCache

ShimCache

Windows

A system compatibility record that serves as evidence of which programs have been executed.

About ShimCache
User MRU

User MRU

Windows

The registry's "Most Recently Used" lists — Run dialog commands, typed Explorer paths, and recently opened files — direct evidence of deliberate, interactive user action.

About User MRU
Recent Lnks

Recent Lnks

Windows

Automatically created shortcuts that show which files a user has recently opened or accessed.

About Recent Lnks
MFT

MFT

Windows

A master index of every file on the disk, including critical information about deleted files.

About MFT
Event Logs

Event Logs

Windows

The computer's diary, recording important system, security, and application events as they happen.

About Event Logs
Network List

Network List

Windows

Every Wi-Fi and wired network a device has ever joined — SSIDs with first and last connection dates — a location and behavior history of the machine itself.

About Network List
Recycle Bin

Recycle Bin

Windows

A critical repository of deleted files and their metadata, revealing exactly what a user attempted to remove and when.

About Recycle Bin
Startup Tasks

Startup Tasks

Windows

A critical record of applications and services configured to execute automatically at boot or user logon, frequently abused by malware to maintain persistence.

About Startup Tasks
AmCache

AmCache

Windows

Tracks programs that have run on a computer, providing a history of application usage.

About AmCache
Slack

Slack

All

A record of user messages and file transfers that provides evidence of conversations and insider threats.

About Slack
SRUM

SRUM

Windows

Details which applications used network data and CPU time, helping to track internet and program activity.

About SRUM
Jumplists

Jumplists

Windows

Reveals recently opened files, showing a history of a user's document and application access.

About JumpLists
UserAssist

UserAssist

Windows

Tracks applications launched via the Windows graphical user interface, revealing specific user activity, run counts, and execution times.

About UserAssist
Prefetch

Prefetch

Windows

A performance-enhancing artifact that provides definitive proof of application execution, run counts, and the specific files accessed during launch.

About Prefetch
PS History

PS History

Windows

A command log that reveals specific, advanced actions performed by administrators or sophisticated users.

About PS History
USN Journal

USN Journal

Windows

A hidden system log that records changes made to files and directories, revealing a timeline of file creation, modification, and deletion.

About USN Journal
RDP Client

RDP Client

Windows

The client-side diary of every Remote Desktop session a user has initiated — servers, usernames, and settings, recorded in the user's own registry hive.

About RDP Client
Profile Lists

Profile Lists

Windows

Identifies every user account that has logged into the computer and their associated profile folder.

About Profile Lists

Join the future of forensics.

Start with a flat-fee Compromise Assessment — fully credited toward a subscription.

Book a Demo