Jump lists
Jump lists are a feature of the Windows taskbar that allow users to see a list of recently accessed items. Of course, this feature can also be used by digital forensic analysts and incident responders to examine the list of recently accessed files.
These files can be found at C:\%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations
.
There's a GUI tool for browsing the contents of such files – JumpList Explorer:
As you can see in the preceding screenshot, jump lists contain information not only about accessed files, but also, for example, about hosts accessed via RDP! It's extremely useful when we are investigating lateral movement.
But what about data exfiltration? Let's look at System Resource Usage Monitor (SRUM)!