drop security evtx csv and shimcache or prefetch csv · detect execution evidence occurring outside known login sessions · identify executions that cannot be attributed to any user session · surface phantom execution gaps indicating anti-forensic log manipulation · runs locally
Security 4624/4634/4647/4800/4801 · shimcache · prefetch · BAM/DAM last-run timestamps
drop security evtx csv · shimcache · prefetch · BAM/DAM csv