What is the “Network List” Windows forensic artifact?
Windows maintains a profile for every network a device has ever connected to, stored in the SOFTWARE registry hive. Each Network List entry records the network’s identifying name or SSID, the date of first connection, and the date of most recent connection — along with whether the profile was treated as a managed (trusted) or unmanaged network. Over months and years, this quietly accumulates into something remarkable: a travel and behavior history of the machine itself, written by the operating system with no agent required.
For a DFIR investigator, Network List profiles place a device in context. They can establish that a laptop joined a hotel or conference network during the very window when sensitive data left it, reveal connections to unauthorized or rogue access points, or expose a personal hotspot being used as an unsanctioned exfiltration channel. Because these records persist long after the connections end — and are routinely overlooked during cleanup — they often corroborate timelines that every other artifact merely suggests.
Enterprise Forensic Applications
Network history is a force multiplier in Insider Risk & HR Investigations: TensorGuard correlates Network List profiles with staging and exfiltration timelines to show not just what left a device, but where the device was when it left — off the corporate network, on a personal hotspot, at a location the employee had no business reason to be. In compromise investigations, unexpected network joins around an intrusion window help reconstruct an attacker’s path and rule out — or confirm — insider involvement with evidence rather than assumption.
Collecting, Decoding, and Viewing “Network List” with TensorGuard
- Create a TensorGuard account and sign in to the TensorGuard console at https://app.tensorguard.com.
- Select “Case Manager”, then the plus button to create a case. This will contain your enrolled devices, their reports, and any manually submitted collections.
- Linked inside the case menu, download the TensorGuard Forensic Collector and run it on your target system.
- In the console, click the plus button for “New Enrollment”, copy the enrollment key, and paste it into the TensorGuard Forensic Collector on your target device.
- Now that you have a device enrolled, select the device(s), and click “Send Signal”. Answer the questions regarding what you want to look for in the analysis, any alerting on positive findings, and if the collection and analysis should be recurring.
- Once the report is generated, you’ll have Network List delivered in the browser, alongside an executive summary and timeline of findings.
Get Started
TensorGuard™ is a trademark of TensorGuard Inc. All other trademarks are the property of their respective owners. The information provided on this website is for educational and informational purposes only and does not constitute legal, forensic, or professional advice. Due to the complexities of Digital Forensics and potential legal implications, you should always consult with qualified legal counsel or a certified digital forensics expert before taking action based on findings.
Network List
Windows
Every Wi-Fi and wired network a device has ever joined — SSIDs with first and last connection dates — a location and behavior history of the machine itself.
Start with a Compromise Assessment.
One flat fee, fully credited toward a subscription. We conduct a complete, AI-driven Compromise Assessment across your critical systems — with evidence-linked findings your team can validate in minutes.

