Insider Threat Matrix™

  • ID: DT061
  • Created: 12th June 2024
  • Updated: 17th June 2024
  • Platform: Windows
  • Contributor: The ITM Team

Notepad.exe TabState

The contents of Notepad sessions can be recovered, even if the user has not saved the .txt file. This artifact is located in C:\Users\[Username]\AppData\Local\Packages\Microsoft.WindowsNotepad_8wekyb3d8bbwe\LocalState\TabState.


Each Notepad tab will have three files [GUID].bin, [GUID].0.bin, [GUID].1.bin where [GUID].bin is the actual tab content. This file can be opened to retrieve the strings in any text editor, or PowerShell can be used with the Get-Content cmdlet to read a specific file, or read all .bin files in a location: Get-Content *.bin.