Detections
- Home
- - Detections
- -DT061
- ID: DT061
- Created: 12th June 2024
- Updated: 17th June 2024
- Platform: Windows
- Contributor: The ITM Team
Notepad.exe TabState
The contents of Notepad sessions can be recovered, even if the user has not saved the .txt file. This artifact is located in C:\Users\[Username]\AppData\Local\Packages\Microsoft.WindowsNotepad_8wekyb3d8bbwe\LocalState\TabState
.
Each Notepad tab will have three files [GUID].bin, [GUID].0.bin, [GUID].1.bin where [GUID].bin is the actual tab content. This file can be opened to retrieve the strings in any text editor, or PowerShell can be used with the Get-Content cmdlet to read a specific file, or read all .bin files in a location: Get-Content *.bin
.