Key Folders

Windows VersionSystem FolderRoot Folder (User folder)
Windows 2000C:\WINNTC:\Documents and Settings
Windows XPC:\WindowsC:\Documents and Settings
Windows Vista onwardsC:\WindowsC:\Users
  • System folder — Stores information about the operating system (i.e.: Event logs)
  • Root folder — Stores information pertaining to the user (i.e.: user configs, user files)

NTUSER.DAT

  • File that stores user configurations for installed apps & Windows itself
  • Updated when the user logs out → Can be used to determine last access time by user
  • Located in the root folder (C:\Users\%USERNAME%)

Recycle Bin

  • Used to temporarily store deleted files
  • Located at C:\Users\%USERNAME%\$RECYCLE.BIN\<SID>
  • File name & file content are split up
Windows VersionFile NameFile Content
Windows 2000 & XPRecycler (Recycle bin’s folder name)Hidden file named INFO2
Windows Vista onwardsIndex file, named $I<random_number>.<extension>Renamed file, named $R<random_number>.<extension>

Juicy Folders

Low Folders

  • Used by Internet Explorer
  • Configured with low privileges to store files from the internet for security reasons
  • Contains cookies, temporary internet files & history

Other Folders

The table below shows a list of common folders that can contain juicy information. Fields marked as - under “What it Contains” are self-explanatory.

Most of the Windows related configurations are stored at C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Windows.

NameApplicationsWhat it Contains
Email FoldersWindows Mail-
Messaging HistorySkype, MSTeams-
Recent FoldersWindows OSShortcuts (link files) to recently accessed folders & applications
Documents / DesktopWindows OS-
Sent to FolderWindows OSUsed to store files to send to applications (triggered by Right Click > Send to)
Temp FolderWindows OS-