WHAT YOU WILL PRODUCE
A sourced timeline with explicit confidence, clock assumptions and alternative explanations.
Frame a question before collecting everything
A useful Windows investigation starts with a question: was a named program executed on this host during a particular period, and what evidence supports that conclusion? Define the host, users, time window and available sources. Record any containment or recovery actions that have already changed the system.
This guide assumes an authorized collection or forensic training image. Live response and offline examination have different effects on a system. Choose and document the acquisition approach before collecting, and preserve the acquisition log with the evidence.
Establish the evidence set
Assign identifiers to the disk image, event-log export and any separately acquired application or memory data. Record the source host, acquisition start and end, examiner, tool version and timezone. Preserve a master copy and use a verified working copy.
A hash comparison supports byte-level consistency between files. It cannot establish collection completeness or prove an event occurred. For a supplied file, calculate SHA-256 and record its size alongside the digest:
Get-FileHash -LiteralPath '.\evidence\training-image.E01' -Algorithm SHA256
For segmented images, retain and inventory every segment. Use the acquisition tool's documented verification as well; a hash of one container segment is not a verification of the entire acquired medium.
Know what each artifact can support
| Artifact family | A useful question | Interpretation boundary |
|---|---|---|
| Security event logs | Which audited logon or process records exist? | Audit configuration, retention and collection gaps |
| Filesystem metadata | Which file records and recorded times exist? | Copying, updates and clock differences affect meaning |
| Application and browser data | What did the application record? | Synchronization, caching and profile scope |
| Recent-item artifacts | Which objects appear in recorded application activity? | Presence does not automatically establish intent |
| Acquired memory | What was represented at acquisition time? | A volatile snapshot, not a complete history |
Microsoft documents event 4688 as a process-creation audit event. Its fields and availability depend on auditing and configuration; command-line content is not guaranteed. Consult the event documentation rather than assuming a missing field means the process had no arguments.
Make ingestion reviewable
If using Autopsy on a training image, create a named case, add the supplied image and record the selected ingest modules before processing. Keep case output separate from the image. Review processing warnings and record which modules completed. The Autopsy user documentation explains its data-source and analysis workflow; check documentation matching your installed version.
Do not treat “processing complete” as validation of every result. Pick a relevant finding and verify its source path, record identity and raw time. Export the record and retain enough context to locate it again.
Correlate time explicitly
Use separate fields for raw timestamp, source timezone or offset, normalized UTC and event meaning. Keep collection time separate from the time represented by an artifact. Record host clock differences if a trusted comparison is available; otherwise state the uncertainty.
Imagine a synthetic case with a download record at 09:00 UTC, a file record at 09:00:02 and a process-creation record at 09:01. Together they support a sequence to investigate. They do not by themselves identify the person operating the session or prove the file was malicious.
The downloadable synthetic timeline includes source locators and limitations. Add the supporting evidence identifier to every real case row.
Test the strongest claim
For a proposed finding, ask what else could explain the records. A scheduled task, software deployment, remote-support session or synchronization event may produce activity that superficially resembles a user action. Compare the observed sequence with approved administration and independently collected logs.
Record contradictions instead of hiding them. If one parser and another disagree about a time or event meaning, preserve both outputs, check the underlying record and explain the resolution. If it remains unresolved, qualify the finding.
A small exercise
Use a purpose-built training image or your own benign test dataset. Select one program execution, locate two distinct artifact families relating to it and write a 150-word finding. Include a precise observation, your interpretation and an alternative explanation. A second reviewer should be able to reproduce the observation from your locators.
Close the case record
Deliver the scope, collection inventory, hashes, processing log, sourced timeline and limitations. Do not describe a lack of retained logs as proof of no activity. Separate technical observations from decisions about responsibility or intent.
Start with the case worksheet and retain the original acquisition context with every export.