SKIP TO CONTENT
ARTIFACT INDEX

The Digital Forensic Artifact Index

One page per artifact, written for the lawyer who has to decide what a finding is worth. Each entry says what the record contains, what it will support, and — the field that matters most — what it will not support however strongly it points.

ENTRIES
36 artifacts
CATEGORIES
8
EVERY ENTRY
Proves · cannot prove · survives
PLATFORMS
Windows · macOS · cloud
SCOPE
Host, server and tenant records
COST
Free · no sign-up
IN SHORT

A digital forensic artifact is a record an operating system, application, or cloud service writes as a side effect of ordinary use — a registry key, a shortcut file, a journal entry, an audit log row. Each one records something narrow and specific. This index covers 36 of them, and for every entry it states what the artifact proves, what it cannot prove, how opposing counsel attacks it, and how long it survives.

How to read an entry

The most common way a computer forensic opinion fails is not bad acquisition — it is an inference stated more strongly than the artifact supports.

An artifact records one thing. An expert then says it shows a slightly larger thing, and by the time the opinion reaches a report it has grown into a claim the artifact never supported. Device connection history becomes proof of copying. A shortcut file becomes proof of exfiltration. Each entry here is laid out to make that drift visible, which is why what it cannot prove sits beside what it proves at the same weight rather than underneath it as a footnote.

  • Where it lives — the registry path, file path, or log channel, so a preservation request can name it.
  • What it records — what is actually written, and when the write happens.
  • Proves and cannot prove — two equal panels. The second is the reason to trust the first.
  • How it is attacked — the cross-examination the finding has to survive.
  • What survives — retention and rollover, which decide more matters than analysis does.

Three distinctions run through every entry. An account is not a person. Access is not exfiltration. And the absence of a record is not the absence of an event, because artifacts age out, roll over, and are switched off by configuration. If you would rather start from the claim than from the artifact, Can This Artifact Prove That? maps six claims litigators routinely need to support onto the records that bear on each. Vocabulary used here is defined in the forensic glossary.

FILTER BY CATEGORY
FILTER BY PLATFORM

SHOWING 36 OF 36 ARTIFACTS

USB and Removable Media

Records showing that a removable device was attached to a machine, which device it was, when it first appeared, and which user account mounted it. None of them record file transfer, which is the inference these artifacts are most often asked to carry and cannot.

File and Folder Access

Records created when a path is opened, browsed, or searched through the shell. They are the strongest evidence that a named file or folder was interacted with, and they are silent on whether it was read, copied, or merely displayed in a window.

Program Execution

Records bearing on whether a program ran. The distinctions inside this category decide cases: presence of a binary, metadata about a binary, and evidence of execution are three different findings supported by three different artifacts, and only some of them attribute the act to a user.

Deletion and Recovery

What is left after a file is removed, and where earlier versions of it may still exist. Deletion normally unlinks rather than overwrites, so the question is usually not whether anything survives but which partial records survived and how far back they reach.

Filesystem Metadata and Timestamps

The filesystem's own metadata and journals: what NTFS wrote about a file, in what order, and how granular the record is. These are the artifacts that test whether a timeline built from anything else is telling the truth.

Accounts and Authentication

Records tying a session to an account. The gap between an account and a person is the most exploited weakness in digital evidence, and it is closed by corroboration from outside the machine rather than by any artifact in this category.

Network and Remote Activity

Records of activity that crossed a network boundary — browsing, remote sessions, and per-application transfer volume. These can supply a quantity where endpoint artifacts supply only an inference, and they age out faster than almost anything else on the disk.

Cloud and Sync

Sync-client records on the endpoint and audit records in the tenant. Together they cover the exfiltration channel that leaves no device history at all, and they are governed by retention windows short enough that preservation timing usually decides what is available.

The eight categories

The index is grouped the way an examination is scoped, from the endpoint outward: what was attached to the machine, what was opened on it, what ran on it, what was deleted from it, what the filesystem itself recorded, who was signed in, what crossed the network, and what the tenant kept after the endpoint was wiped.

A FINDING YOU NEED TESTED

If an opposing expert has built an opinion on one of these artifacts — or you need one of your own stated at a level that survives cross — Law & Forensics retains court-tested digital forensic expert witnesses and forensic neutrals.

A conflicts check and scoping call follow, normally within one business day. Please do not send privileged or case-sensitive material until conflicts have cleared.

WEEKLY BRIEFING

Digital evidence, explained for litigators.

One email a week on forensic method, digital evidence, and expert testimony — written for counsel, not for technicians. No pitches.

DOUBLE OPT-IN · UNSUBSCRIBE ANY TIME · PRIVACY POLICY

  • Can This Artifact Prove That?

    Start from the claim instead of the artifact: six claims, the records that bear on each, and what no combination of them establishes.

  • Forensic glossary

    108 terms defined for litigators — what each one is, why a case turns on it, and what happens in the matter when it is mishandled.

  • Computer forensics

    The endpoint examination these artifacts come from: acquisition, analysis, and a report written to be tested.

  • Cloud forensics

    Tenant-side records — audit logs, sign-in logs and sync history — and the retention windows that close before a complaint is filed.

  • Daubert and digital evidence

    Why an opinion stated one level too strongly is an admissibility problem under Rule 702(d) rather than a point for cross.

  • Expert witness testimony

    What happens when a finding built on one of these artifacts has to be defended in a deposition or on the stand.

Attorney advertising / expert services. This page describes forensic artifacts and the procedural rules that govern expert evidence in general terms. Artifact behaviour varies by operating-system version, build, and configuration, and every observation has to be verified against the system actually in front of you. Nothing here is legal advice, and it is not a substitute for checking the rules, standing orders, and case law of your own forum.