DFIR Artifact Quick Reference
DFIR Artifact Quick Reference Audience: DFIR practitioners conducting Windows-centric incident response and forensic investigations. Scope: Windows 10/11, Server 2016–2022 unless noted. Legend: [EZ] = Eric Zimmerman tool | [TS] = Triaged from live system | …