Tool

Evidence-gap checker

Say what you are trying to establish. This gives you the sources that would establish it, in the order to collect them, with the ones that expire first at the top, and the source people commonly reach for that does not actually settle the question.

An account authenticated to this host interactively from elsewhere.

collect, in this order

  1. logon events

    Collect it. The full entry, paths, retention and limitations, lives in the artifact reference, and this one is part of membership.

  2. Prefetch

    C:\Windows\Prefetch\<NAME>-<HASH>.pf

    survivesUntil rolled out by the 1024-entry cap. On a normal workstation this is months.

    does not proveWHO ran it — Prefetch carries no user context at all

  3. shellbags

    Collect it. The full entry, paths, retention and limitations, lives in the artifact reference, and this one is part of membership.

  4. lnk files

    Collect it. The full entry, paths, retention and limitations, lives in the artifact reference, and this one is part of membership.

the trap

A 4624 on its own. Logon Type is what separates RDP (type 10) from a share mount (type 3), and the source IP may be a pivot rather than the origin: the same account arriving from three hosts in an hour is the finding, not any single event.

if you find nothing

The Security log is 20MB by default. On a domain controller that can be under a day, so a gap usually means the log rolled, not that nothing happened.

Worked a case where this list was wrong or incomplete? That is worth more than the list is. Say so.