Tool

Evidence-gap checker

Say what you are trying to establish. This gives you the sources that would establish it, in the order to collect them, with the ones that expire first at the top, and the source people commonly reach for that does not actually settle the question.

Data was collected on this host and sent out.

collect, in this order

  1. srum

    Collect it. The full entry, paths, retention and limitations, lives in the artifact reference, and this one is part of membership.

  2. usn journal

    Collect it. The full entry, paths, retention and limitations, lives in the artifact reference, and this one is part of membership.

  3. recyclebin

    Collect it. The full entry, paths, retention and limitations, lives in the artifact reference, and this one is part of membership.

  4. lnk files

    Collect it. The full entry, paths, retention and limitations, lives in the artifact reference, and this one is part of membership.

  5. shellbags

    Collect it. The full entry, paths, retention and limitations, lives in the artifact reference, and this one is part of membership.

the trap

SRUM byte counts alone. SRUM tells you how much a process sent, never where, pairing it with network or proxy logs is what turns a volume into a destination.

if you find nothing

Staging archives are routinely built and deleted. The USN journal records both after the file is gone, which is why it outranks looking for the archive itself.

Worked a case where this list was wrong or incomplete? That is worth more than the list is. Say so.