Windows Artefacts
Enumerates every user‑specific COM class identifier (CLSID) stored in the
UsrClass hiveRegistry
Extracts every CLSID registration stored in the machine‑wide
Software hiveRegistry
Extracts every pieces of metadata that is stored in a Windows Shell Link file
LnkBatched
Parses files produced by the GetObjInfo utility, extracting Windows object information from the object manager namespace
Csv
Extracts detailed information from Windows Registry hive files
HiveKey
Srum table that tracks stores the per‑process estimates of how much electrical energy Windows thinks each component has consumed over time
Srum
Srum table that tracks long term, per‑process estimates of how much electrical energy Windows thinks each component has consumed over time
Srum
Parse data from Srum
tagged_energy table {B6D82AF1-F780-4E17-8077-6CB9AD8A6FC4} ()Srum
Parse data from Srum
vfuprov table {7ACBBAA3-D029-4BE4-9A7A-0885927F1D8F}Srum
Srum table that tracks telemetry that Windows collects about the Windows Push Notification (WPN) service – i
Srum