SKIP TO CONTENT
PROGRAM EXECUTION12 / 36

Prefetch

Also called prefetch files, .pf files, Windows prefetch forensics.

PLATFORM
Windows
CATEGORY
Program Execution
INDEX
12 of 36
PROVES
5 findings
CANNOT PROVE
6 limits
QUESTIONS
4 answered
WHAT IT IS

Files Windows writes to speed up program launches, recording that an executable ran, when it last ran, how many times, and which files it loaded on startup.

Where it lives

C:\Windows\Prefetch\NAME-HASH.pf

Name the location in the preservation request rather than describing the artifact in general terms. A request that asks for the record by its path is one the responding party can act on and one a court can enforce; a request for “all forensic evidence of prefetch” is neither.

What it records

On the first run of an executable Windows creates a prefetch file named for the binary and a hash of its path, and updates it on subsequent runs. It records a run count, the volumes involved, and a list of files and directories referenced during the opening seconds of execution. Windows 8 and later retain the last eight run times in each file; Windows 7 retained one. The directory is capped — 1,024 files on Windows 8 and later — so the oldest entries are removed as new programs run.

What it proves — and what it cannot

These two panels carry equal weight, deliberately. The right-hand column is not a disclaimer: it is the specific, mechanical reason an inference fails, and it is the column opposing counsel will read back to a witness on cross-examination.

What it proves

FINDINGS THIS ARTIFACT WILL SUPPORT ON ITS OWN TERMS.

  • That a named executable ran on this machine, which is the inference AmCache and ShimCache cannot support
  • The last execution time, and on Windows 8 and later the seven before it
  • A cumulative run count for that binary at that path
  • Which files and directories the program touched at startup — often naming documents, archives, or a removable volume the program was pointed at
  • That a program ran which is no longer installed and appears nowhere in installed-software lists, such as a portable archiver or a wiping utility

What it cannot prove

INFERENCES IT WILL NOT CARRY, HOWEVER STRONGLY IT POINTS.

  • Who ran the program. Prefetch carries no user SID and no session identifier, so it establishes execution on the machine and not by whom
  • That the program did anything. Execution and effect are separate findings; a prefetch entry for a wiping tool shows it ran, not what it deleted
  • That the run count is a lifetime total. The counter belongs to the prefetch file, so a file deleted and recreated starts again from one, and a binary run from a different path gets a different file with its own count
  • That a program did not run. Prefetch is disabled by default on Windows Server, can be switched off by policy or registry value, and the directory cap silently removes the oldest entries
  • Timing beyond the retained run times. Windows 8 and later hold eight; everything before the oldest of them is unrecorded
  • That the executable was the version in evidence. The file name and path hash identify a path, not a hash of the binary's contents

How the finding is attacked

An opinion built on this artifact meets these arguments. Each of them is answerable, and each of them is answered before the report is served rather than at a deposition.

  • Establishing that prefetching was disabled on the system, which makes the absence of entries uninformative
  • Pointing out the missing user attribution on a machine with several accounts or an active remote session
  • Showing the directory cap evicted entries covering the period at issue
  • Arguing that execution of a tool is consistent with legitimate use, and that the artifact records no arguments, no targets, and no outcome
  • Noting that the run count restarts if the prefetch file was deleted, so a low count does not mean infrequent use

What survives, and for how long

Prefetch files persist across reboots and outlive uninstallation of the program, but the directory is capped so entries are evicted as other programs run — on a busy workstation the window can be months, on a heavily used one much less. Deleting the directory is trivial and leaves the timing gap as the only sign.

More matters are decided by what an artifact never kept than by what it says, which makes preservation timing the most consequential decision in the matter — and it is usually made months before anyone examines anything. The evidence preservation deadline calculator works from the date you first anticipated litigation.

Questions counsel ask

Does prefetch prove a program was run?

Yes — prefetch is the Windows artifact that genuinely supports an execution inference, which AmCache and ShimCache do not. A prefetch file exists because Windows observed the binary start. What it does not carry is a user SID, so it establishes that the program ran on that machine rather than who ran it, and it says nothing about what the program did once running.

How many run times does a prefetch file store?

Windows 8 and later store the last eight execution times in each prefetch file; Windows 7 stored one. There is also a cumulative run count. Anything before the oldest retained time is unrecorded, so a prefetch file showing eight runs in a week does not mean the program was not run fifty times the month before.

Why is there no prefetch file for a program that was run?

Several ordinary reasons. Prefetching is disabled by default on Windows Server and can be switched off by policy or a registry value on any system. The prefetch directory is capped at 1,024 files on Windows 8 and later, so entries are evicted as other programs run. And the directory can simply be deleted. Absence of a prefetch file is weak evidence that a program never ran.

Can a prefetch run count be reset?

Yes. The count belongs to the prefetch file rather than to the binary, so deleting the file and running the program again starts the count at one. Running the same executable from a different path produces a separate prefetch file with its own independent count. A low run count is therefore not evidence of infrequent use without checking the file's own creation time.

Terms used on this page

Every term below is defined in the forensic glossary — what it is, why a case turns on it, and what happens when it is mishandled.

No artifact carries a matter on its own. These are the records that corroborate, contradict, or supply the timeline this one cannot.

A FINDING ON THIS ARTIFACT

Whether the prefetchevidence in your matter supports the opinion built on it is a question with a testable answer. Law & Forensics retains court-tested digital forensic expert witnesses and forensic neutrals.

A conflicts check and scoping call follow, normally within one business day. Please do not send privileged or case-sensitive material until conflicts have cleared.

WEEKLY BRIEFING

Digital evidence, explained for litigators.

One email a week on forensic method, digital evidence, and expert testimony — written for counsel, not for technicians. No pitches.

DOUBLE OPT-IN · UNSUBSCRIBE ANY TIME · PRIVACY POLICY

  • Can This Artifact Prove That?

    Start from the claim rather than the artifact: which records bear on it, and what no combination of them establishes.

  • Computer forensics

    The examination this artifact is collected and analysed in, scoped to a matter and reported so it can be tested.

  • The artifact index

    All 36 entries, grouped by what they bear on and filterable by platform.

  • Daubert and digital evidence

    Why an opinion stated one level too strongly is an admissibility problem rather than a point for cross-examination.

← BACK TO THE ARTIFACT INDEX

Attorney advertising / expert services. This page describes forensic artifacts and the procedural rules that govern expert evidence in general terms. Artifact behaviour varies by operating-system version, build, and configuration, and every observation has to be verified against the system actually in front of you. Nothing here is legal advice, and it is not a substitute for checking the rules, standing orders, and case law of your own forum.