How to Use This Field GuideMicrosoft WindowsStep 1: Identify the users and basic system contextStep 2: Determine what programs were executedStep 3: Determine what files existed and what happened to themStep 4: Reconstruct user activity in Windows ExplorerStep 5: Determine web activity and downloadsStep 6: Determine whether external devices were connectedStep 7: Determine what happened on the systemStep 8: Determine network and application usageApple macOSStep 1: Identify users and system contextStep 2: Determine what applications were executedStep 3: Determine file activityStep 4: Reconstruct user file interactionStep 5: Determine whether files were deletedStep 6: Determine web browsing activityStep 7: Determine whether external devices were connectedStep 8: Examine system and application logsStep 9: Identify network and system usageLinuxStep 1: Identify system configuration and usersStep 2: Identify user logins and authentication activityStep 3: Determine command execution historyStep 4: Determine program execution and persistenceStep 5: Examine file system activityStep 6: Review system and application logsStep 7: Determine network configuration and remote accessStep 8: Examine package management artifactsStep 9: Examine running services, processes, and exposed functionalityApple iOSStep 1: Identify the device and user contextStep 2: Determine installed applications and app ownershipStep 3: Reconstruct communications activityStep 4: Determine browser and internet activityStep 5: Identify photos, videos, and user filesStep 6: Determine location history and movementStep 7: Examine user interactions and runtime behaviorStep 8: Examine system, diagnostics, and wireless artifactsStep 9: Examine backups and synced-device dataAndroidStep 1: Identify the device, users, and system contextStep 2: Determine installed applications and app ownershipStep 3: Reconstruct communications activityStep 4: Examine browser and internet activityStep 5: Identify photos, videos, screenshots, and user filesStep 6: Determine location activity and movementStep 7: Examine wireless and network artifactsStep 8: Examine system, usage, and diagnostic artifactsStep 9: Examine downloads, documents, and transferred filesMemory (RAM)Step 1: Identify the operating system and memory-image contextStep 2: Identify running processes and process relationshipsStep 3: Determine user context and execution identityStep 4: Determine how a process was launchedStep 5: Examine loaded modules, DLLs, and librariesStep 6: Examine memory regions and look for injected codeStep 7: Examine file handles, open objects, and in-memory file referencesStep 8: Examine network connections and listening servicesStep 9: Recover user artifacts from memory