logo

Reconstructing User Activity for Forensics with FeatureUsage

ID: cb92d065-4288-5aa3-b89c-355cb8b96855

STIX ID: report--cb92d065-4288-5aa3-b89c-355cb8b96855

Feed Name: Group-IB Blog

Date Published: 2020-04-28

Date Updated: 2026-04-27

...
...

This report describes the Windows 10 FeatureUsage registry artifacts located at NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Explorer\FeatureUsage and how each subkey—AppBadgeUpdated, AppLaunch, AppSwitched, ShowJumpView, and TrayButtonClicked—records taskbar-related actions. It explains how these entries can be leveraged in digital forensics and incident response to reconstruct user activity and evidence of execution (e.g., app launches and switches indicative of tools like Mimikatz).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.