Apps Leave Traces: Forensic Insights from the Microsoft Store
ID: b4cd912d-0803-5c9a-94ad-1aa707339716
STIX ID: report--b4cd912d-0803-5c9a-94ad-1aa707339716
Feed Name: Detect FYI
This research post presents a practical forensic methodology for analyzing Microsoft Store app activity on Windows 10/11, covering default installation and user-data locations, Store vs. WinGet installation paths, Group Policy and update behavior (including pause settings), and user interaction artifacts (custom jump lists and cached images). It details how to correlate the StateRepository database—especially the SRHistory table—with tailored SQL queries and AppXDeploymentServer Operational event logs to build timelines of installations, updates, and removals and to distinguish user-initiated from system-initiated actions, alongside caveats (e.g., SRHistory retention) and a case-study workflow.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
