UserAssist
Also called UserAssist registry key, ROT13 registry, GUI program launches.
- PLATFORM
- Windows
- CATEGORY
- Program Execution
- INDEX
- 15 of 36
- PROVES
- 4 findings
- CANNOT PROVE
- 5 limits
- QUESTIONS
- 3 answered
A per-user registry record of programs and shortcuts launched through the Windows graphical shell, with a run count, focus time, and the last execution time.
Where it lives
NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{GUID}\Count
Name the location in the preservation request rather than describing the artifact in general terms. A request that asks for the record by its path is one the responding party can act on and one a court can enforce; a request for “all forensic evidence of userassist” is neither.
What it records
Explorer maintains counters for items the user launched through the interface, stored under GUID subkeys that separate executables from shortcut links, with value names obfuscated by a simple character rotation. Each value holds a run count, a focus count and accumulated focus time, and a last-execution timestamp. The count's baseline has differed across Windows versions, so an absolute number should be read with the version in mind rather than as a raw tally.
What it proves — and what it cannot
These two panels carry equal weight, deliberately. The right-hand column is not a disclaimer: it is the specific, mechanical reason an inference fails, and it is the column opposing counsel will read back to a witness on cross-examination.
What it proves
FINDINGS THIS ARTIFACT WILL SUPPORT ON ITS OWN TERMS.
- That a specific user account launched a named program or shortcut through the graphical shell
- The last time that account launched it
- A run count and accumulated foreground focus time, which distinguishes a program opened once from one used for hours
- User-level attribution for execution, which prefetch cannot supply — the reason the two are read together
What it cannot prove
INFERENCES IT WILL NOT CARRY, HOWEVER STRONGLY IT POINTS.
- That a program never ran. UserAssist records launches through the graphical shell only; anything started from a command prompt, a script, a scheduled task, or a service creates no entry
- That the run count is exact. Baselines and increment behaviour have varied across Windows versions, and the value should be characterised rather than quoted as a bare number
- What the program did, or what files it touched. There are no arguments and no targets in the record
- That the person named on the account performed the launch, as opposed to anyone using that logged-on session
- That focus time reflects attention. Accumulated foreground time counts a window being in front, not a person at the desk
How the finding is attacked
An opinion built on this artifact meets these arguments. Each of them is answerable, and each of them is answered before the report is served rather than at a deposition.
- Showing the program at issue is ordinarily launched by script or command line, so its absence proves nothing
- Questioning the run-count baseline for the Windows version examined
- Arguing that a shared or unlocked session breaks the account-to-person link
- Pointing out that the key is per-user and easily cleared, so an empty key is not an empty history
What survives, and for how long
The values persist in the user hive across reboots and survive uninstallation of the program. They are cleared by profile deletion and by cleanup utilities, and they do not survive a wipe and reinstall.
More matters are decided by what an artifact never kept than by what it says, which makes preservation timing the most consequential decision in the matter — and it is usually made months before anyone examines anything. The evidence preservation deadline calculator works from the date you first anticipated litigation.
Questions counsel ask
What does UserAssist prove?
UserAssist proves that a specific user account launched a named program or shortcut through the Windows graphical interface, and it records the last launch time, a run count and accumulated foreground focus time. It is the artifact that supplies user attribution for execution, which prefetch does not, and the two are normally read together for that reason.
Why would a program a user ran not appear in UserAssist?
Because UserAssist records launches through the graphical shell only. A program started from a command prompt, by a script, through a scheduled task, or as a service leaves no entry. That covers most of what is interesting in an anti-forensics or exfiltration question, so an absent UserAssist entry is weak evidence that a program was not run.
Is the UserAssist run count reliable?
It is reliable enough to distinguish heavy from occasional use, and it should not be quoted as an exact tally. The counter's baseline and increment behaviour have differed across Windows versions, so an examiner reporting a number should say which build produced it. Focus time is the more informative field in practice, because it separates a program opened once from one used for hours.
Terms used on this page
Every term below is defined in the forensic glossary — what it is, why a case turns on it, and what happens when it is mishandled.
Related artifacts
No artifact carries a matter on its own. These are the records that corroborate, contradict, or supply the timeline this one cannot.
Prefetch
Files Windows writes to speed up program launches, recording that an executable ran, when it last ran, how many times, and which files it loaded on startup.
BAM and DAM
A registry record, organised by user SID, of the last execution time of individual executables — the rare Windows artifact that attributes execution to an account directly.
ShimCache (AppCompatCache)
A capped registry cache of file paths the compatibility layer evaluated, holding each file's path and its last-modified time — and, on modern Windows, no reliable indicator of execution.
Windows Timeline (ActivitiesCache)
A per-user database recording application usage and the documents opened in each application, with start and end times and, where account sync was on, activity from the user's other devices.
Whether the userassistevidence in your matter supports the opinion built on it is a question with a testable answer. Law & Forensics retains court-tested digital forensic expert witnesses and forensic neutrals.
A conflicts check and scoping call follow, normally within one business day. Please do not send privileged or case-sensitive material until conflicts have cleared.
- Can This Artifact Prove That?
Start from the claim rather than the artifact: which records bear on it, and what no combination of them establishes.
- Computer forensics
The examination this artifact is collected and analysed in, scoped to a matter and reported so it can be tested.
- The artifact index
All 36 entries, grouped by what they bear on and filterable by platform.
- Daubert and digital evidence
Why an opinion stated one level too strongly is an admissibility problem rather than a point for cross-examination.
Attorney advertising / expert services. This page describes forensic artifacts and the procedural rules that govern expert evidence in general terms. Artifact behaviour varies by operating-system version, build, and configuration, and every observation has to be verified against the system actually in front of you. Nothing here is legal advice, and it is not a substitute for checking the rules, standing orders, and case law of your own forum.