February 2026
Intermediate to advanced
456 pages
17h 3m
English
Windows has a wide range of additional artifacts that may be useful in your forensic examination. A few of those will be explained in the following sections.
Windows reports errors that occur with software. This will usually only be of interest in malware investigations. Malware is frequently not developed with extensive software engineering and testing methods, so errors are common. You can find these error reports at:
C:\ProgramData\Microsoft\Windows\WER\ReportArchive
C:\ProgramData\Microsoft\Windows\WER\ReportQueue
C:\Users\XXX\AppData\Local\Microsoft\Windows\WER\ReportArchive
C:\Users\XXX\AppData\Local\Microsoft\Windows\WER\ReportQueu
The reports can be viewed with a standard text editor. An example ...
Read now
Unlock full access