Knowledge Base

Eye
Describe

Comprehensive guides and interactive visualizations for Windows internals and forensic artifacts.

Eye Describe Anatomy

Explore the binary structure and logic of Windows artifacts through interactive modules. The same knowledge base grounds Eye AI — the digital forensics AI assistant for Windows, Crow-Eye's AI forensics assistant.

Visualizer
Prefetch Anatomy
Interactive forensic dissection of Windows Prefetch (.pf) files. Visualize headers, file metrics, and execution history.
Explore Anatomy
Visualizer
LNK File Anatomy
Interactive breakdown of the ShellLink (.LNK) binary format. Visualize headers, IDLists, and extra data blocks.
Explore Anatomy
Visualizer
NTFS MFT Anatomy
Dissect the 1024-byte FILE record. Visualize the header, $STANDARD_INFORMATION, $FILE_NAME, $DATA, and the attribute stream.
Explore Anatomy
Visualizer
SRUM Anatomy
The System Resource Usage Monitor — an ESE database (SRUDB.dat) of per-app, per-user resource use, snapshotted hourly. Its providers, the SruDbIdMapTable, retention, and what it proves.
Explore Anatomy
Visualizer
USN Journal Anatomy
NTFS's change log. Walk USN_RECORD_V2 / V3, all 24 reason flags, and the gap-analysis pattern for evicted records.
Explore Anatomy
Logic
Automatic Jump Lists Anatomy
Understand how Windows tracks frequent and recent destinations. Breakdown of the DestList and OLE structure.
View Breakdown
Logic
Custom Jump Lists Anatomy
Analysis of application-specific jump lists. Explore how pinned and custom tasks are stored.
View Analysis
System
Windows Boot Disk Explorer
Interactive exploration of UEFI/GPT boot partitions and critical forensic system files.
Explore Disk
Visualizer
Windows Process Tree
Walk the process genealogy: parent-child relationships, PID/PPID lineage, and how to spot anomalous spawns during triage.
Explore Tree
Visualizer
Registry Forensics Anatomy
Several hundred unrelated artifacts in one container. Which keys answer execution, persistence, device history, user activity and machine identity, and what each one encodes.
Explore Anatomy
Visualizer
Shell Items & Shellbags Anatomy
The shell item, byte by byte, and every registry family that stores one: Shellbags, RecentDocs, the MRU keys. The BEEF0004 block, and whose timestamps those really are.
Explore Anatomy
Visualizer
ShimCache Anatomy
One registry value holding a serialised database. The 0x34 header, the 10ts record, the 1,024-entry cap, and why an entry is not proof a program ran.
Explore Anatomy
Visualizer
AmCache Anatomy
A registry hive no HKEY points at, inventorying the machine's software with SHA-1 attached. Often the last fingerprint of a binary that was deleted.
Explore Anatomy
Visualizer
Browser Forensics Anatomy
Every artifact a browser leaves behind, down to the wire format: the blockfile and Simple Cache magics, EntryStore, cache2's big-endian trailer, SNSS, LevelDB and mozLz4 - byte by byte.
Explore Anatomy

Windows Artifact Documentation — FAQ

What investigators ask when they need the binary structure behind an artifact.

Where can I find documentation on Windows forensic artifact formats?

Here. Eye-Describe documents the on-disk binary structure of the artifacts that matter in a Windows investigation — Prefetch, LNK, the MFT, the USN journal, Jump Lists, the boot disk, the process tree, the registry's forensic artifacts, Shellbags, ShimCache and AmCache — field by field, with the offsets laid out.

What is the binary structure of a Prefetch file?

A Prefetch (.pf) file carries a header with the executable name and path hash, a file-metrics array of every file the program touched while starting, volume information, and — from Windows 8 onward — eight execution timestamps plus a run count. Each field is dissected in the Prefetch anatomy.

Why does the byte layout matter if a tool parses it for me?

Because you have to defend the finding. Knowing where a timestamp lives, and which of several timestamps a field actually is, is what lets you say why a parser's output means what you claim it means — and spot it when the output is wrong.

Is Eye-Describe part of Crow-Eye or separate?

It is the reference companion to the engine. Crow-Eye parses these artifacts across a whole evidence set and puts them on a timeline; Eye-Describe explains what the parser is reading and why each field is forensically significant.

Which artifact proves a program was executed?

No single one does on its own. Prefetch, the Registry's UserAssist and BAM/DAM keys, AmCache, ShimCache and Event Logs each capture a different aspect, and they disagree in useful ways. Crow-Eye's Correlation Engine reconciles them into one timeline.

Do these formats change between Windows versions?

Yes, and it matters. Prefetch changed compression and timestamp count across Windows 7, 8 and 10; Jump Lists arrived with Windows 7. Each page notes the versions it covers so you do not read a Windows 10 layout onto a Windows 7 image.