Windows 디렉토리/파일 검색

Windows 아티팩트 검색

MD5SHA1경로(파일명)
69d6b742c03ee549df74d3d66cdd405f ffdb37bba75a485991dc7579c74d57572f7f84c2 [NTFS]\[root]\Windows\System32\$I30
8d1f9507753b6180288b1966053ad1f3 13da25f56c0efff90bd53cde3a5244138d9d2eb7 [NTFS]\[root]\Windows\System32\$TXF_DATA
733082cf3104bf4b2c7696302634d20c 98c56d8483f6ba9bc22eb5d39d16cec5e351a816 [NTFS]\[root]\Windows\System32\PerfStringBackup.INI
c51e058ad539bd4dab72e698e7828dcd 49387157cd1cdd92969cde9749ef290ed36fd457 [NTFS]\[root]\Windows\System32\license.rtf
b57e5158f2b4c0da60b16b88f42e0eb2 e027af8986b7c11fd37de41050e68e7dd6e0a399 [NTFS]\[root]\Windows\System32\SleepStudy\ScreenOn\ScreenOnPowerStudyTraceSession-2025-04-04-11-31-21.etl
a2ba02004df2cc5d31ec342816255933 34d928f55ae9659f7659aa9ea1f4fd256e3ae3d7 [NTFS]\[root]\Windows\System32\SleepStudy\ScreenOn\ScreenOnPowerStudyTraceSession-2025-04-04-11-28-57.etl
037be52ee3cf10e4b2330fb381aadde2 84ba28233406111d2aefacede596e2cb11f2056f [NTFS]\[root]\Windows\System32\SleepStudy\UserNotPresentSession.etl
473702c1a9e6506384c26bbda8cb8a8b f3af1dfe81892fa53dfb7ec389e96e6494acc29b [NTFS]\[root]\Windows\System32\Microsoft\Protect\S-1-5-18\$I30
e9d070c52c86cb52709563024575f305 7b422edddbeb861a6ce7cb3f6a32f048af633102 [NTFS]\[root]\Windows\System32\Microsoft\Protect\S-1-5-18\98ddec98-4c1d-463f-9063-261a0fcd94ee
ec1314a3c7a498c9edacb7ff4115b414 64d6cda146d6768dfa29132dfb46c4a19b5999cc [NTFS]\[root]\Windows\System32\Microsoft\Protect\S-1-5-18\Preferred
df2f0b67e938998cc99312bcf3ace847 617bf1b39025c90580ffb1add140af0b885fb1d7 [NTFS]\[root]\Windows\System32\Microsoft\Protect\S-1-5-18\a52504f9-d0a0-4bf3-974f-67f0cf90cf26
c13c034b76371318f8a2034cea42fea2 b36eab9b5b0a2d21f5c0fb6a33393c9f76ffce66 [NTFS]\[root]\Windows\System32\Microsoft\Protect\S-1-5-18\User\$I30
9164a3a1e6f041bc17f4b8e544220bb1 a752c490ab9e32d17e195a1c2672df637df176a2 [NTFS]\[root]\Windows\System32\Microsoft\Protect\S-1-5-18\User\57ffb3ec-5567-4154-9b99-9432308d0657
7470ac4cf9e1fb17d5fcbaf9f547ec25 67df2e7984da52ceabbdd696d3f799460a85ce68 [NTFS]\[root]\Windows\System32\Microsoft\Protect\S-1-5-18\User\Preferred
0238d68d72ca5eb8a320e168f5623c8e 23446d9f39f0c366c17b267510747df004ce26e6 [NTFS]\[root]\Windows\System32\Microsoft\Protect\S-1-5-18\User\1b4f9d36-d0b4-49cb-86b3-5e25f20e8882
0edfcf36f32d5f10db28c26707c5b7da 6ce0ae3e0ed4aed77d416772adfce9c75be7b3f7 [NTFS]\[root]\Windows\System32\FNTCACHE.DAT
2bc2546831b054680c6f59888f295e44 803fe601ef245a0ceed55341fdd4381da9c47e1f [NTFS]\[root]\Windows\System32\secpol.msc
69c1753bd5f81501d95132d08af04464 b0aa4b549f325cca9c9dfa6ce1bd6072aeaeac71 [NTFS]\[root]\Windows\System32\secpol.msc\$DSC
49525986566a050aa233a428aa50d83f 1815d03495b2d6825e0cf820cd16f0c3bba2ee52 [NTFS]\[root]\Windows\System32\rsop.msc
69c1753bd5f81501d95132d08af04464 b0aa4b549f325cca9c9dfa6ce1bd6072aeaeac71 [NTFS]\[root]\Windows\System32\rsop.msc\$DSC