PowerForensics
Home
Get Involved
PowerShell Module
Installation
Module Load Process
Cmdlets
Copy-ForensicFile
Get-ForensicAlternateDataStream
Get-ForensicAmcache
Get-ForensicAttrDef
Get-ForensicBitmap
Get-ForensicBootSector
Get-ForensicChildItem
Get-ForensicContent
Get-ForensicEventLog
Get-ForensicExplorerTypedPath
Get-ForensicFileRecord
Get-ForensicFileRecordIndex
Get-ForensicFileSlack
Get-ForensicGuidPartitionTable
Get-ForensicMasterBootRecord
Get-ForensicMftSlack
Get-ForensicNetworkList
Get-ForensicOfficeFileMru
Get-ForensicOfficeOutlookCatalog
Get-ForensicOfficeTrustRecord
Get-ForensicPartitionTable
Get-ForensicPrefetch
Get-ForensicRecentFileCache
Get-ForensicRegistryKey
Get-ForensicRegistryValue
Get-ForensicRunKey
Get-ForensicRunMru
Get-ForensicScheduledJob
Get-ForensicShellLink
Get-ForensicShimcache
Get-ForensicSid
Get-ForensicTimeline
Get-ForensicTimezone
Get-ForensicTypedUrl
Get-ForensicUnallocatedSpace
Get-ForensicUserAssist
Get-ForensicUsnJrnl
Get-ForensicUsnJrnlInformation
Get-ForensicVolumeBootRecord
Get-ForensicVolumeInformation
Get-ForensicVolumeName
Get-ForensicWindowsSearchHistory
Invoke-ForensicDD
Development
Public API
PowerForensics.BootSectors.GuidPartitionTable
PowerForensics.BootSectors.GuidPartitionTableEntry
PowerForensics.BootSectors.GuidPartitionTableEntry.PARTITION_ATTRIBUTE
PowerForensics.BootSectors.MasterBootRecord
PowerForensics.BootSectors.PartitionEntry
PowerForensics.FileSystems.Ext.BlockGroupDescriptor.FLAGS
PowerForensics.FileSystems.Ext.BlockGroupDescriptor
PowerForensics.FileSystems.Ext.Inode.FILE_MODE
PowerForensics.FileSystems.Ext.Inode.FLAGS
PowerForensics.FileSystems.Ext.Inode
PowerForensics.FileSystems.Ext.Superblock.CHECKSUM_TYPE
PowerForensics.FileSystems.Ext.Superblock.CREATOR_OS
PowerForensics.FileSystems.Ext.Superblock.DEFAULT_HASH_VERSION
PowerForensics.FileSystems.Ext.Superblock.DEFAULT_MOUNT_OPTIONS
PowerForensics.FileSystems.Ext.Superblock.ENCRYPTION_ALGORITHMS
PowerForensics.FileSystems.Ext.Superblock.ERRORS
PowerForensics.FileSystems.Ext.Superblock.FEATURE_COMPAT
PowerForensics.FileSystems.Ext.Superblock.FEATURE_INCOMPAT
PowerForensics.FileSystems.Ext.Superblock.FEATURE_RO_COMPAT
PowerForensics.FileSystems.Ext.Superblock.FLAGS
PowerForensics.FileSystems.Ext.Superblock
PowerForensics.FileSystems.Ext.Superblock.REVISION_LEVEL
PowerForensics.FileSystems.Ext.Superblock.STATE
PowerForensics.FileSystems.Fat.DirectoryEntry.FILE_ATTR
PowerForensics.FileSystems.Fat.DirectoryEntry
PowerForensics.FileSystems.Fat.FatVolumeBootRecord
PowerForensics.FileSystems.Fat.FileSystemInformation
PowerForensics.FileSystems.Fat.LongDirectoryEntry
PowerForensics.FileSystems.FileSystemEntry
PowerForensics.FileSystems.HFSPlus.AllocationFile
PowerForensics.FileSystems.HFSPlus.AttributesFile
PowerForensics.FileSystems.HFSPlus.BSDInfo.ADMIN_FLAGS
PowerForensics.FileSystems.HFSPlus.BSDInfo.FILE_MODE
PowerForensics.FileSystems.HFSPlus.BSDInfo
PowerForensics.FileSystems.HFSPlus.BSDInfo.OWNER_FLAGS
PowerForensics.FileSystems.HFSPlus.BTree.DataRecord
PowerForensics.FileSystems.HFSPlus.BTree.DataRecord.RECORD_FLAGS
PowerForensics.FileSystems.HFSPlus.BTree.DataRecord.RECORD_TYPE
PowerForensics.FileSystems.HFSPlus.BTree.HeaderRecord.BTREE_ATTRIBUTE
PowerForensics.FileSystems.HFSPlus.BTree.HeaderRecord.BTREE_KEYCOMPARE
PowerForensics.FileSystems.HFSPlus.BTree.HeaderRecord.BTREE_TYPE
PowerForensics.FileSystems.HFSPlus.BTree.HeaderRecord
PowerForensics.FileSystems.HFSPlus.BTree.KeyedRecord
PowerForensics.FileSystems.HFSPlus.BTree.MapRecord
PowerForensics.FileSystems.HFSPlus.BTree.Node
PowerForensics.FileSystems.HFSPlus.BTree.NodeDescriptor
PowerForensics.FileSystems.HFSPlus.BTree.NodeDescriptor.NODE_KIND
PowerForensics.FileSystems.HFSPlus.BTree.PointerRecord
PowerForensics.FileSystems.HFSPlus.BTree.Record
PowerForensics.FileSystems.HFSPlus.BTree.UserDataRecord
PowerForensics.FileSystems.HFSPlus.CatalogFile
PowerForensics.FileSystems.HFSPlus.CatalogFile.TEXT_ENCODING
PowerForensics.FileSystems.HFSPlus.CatalogFileRecord.FILE_FLAGS
PowerForensics.FileSystems.HFSPlus.CatalogFileRecord
PowerForensics.FileSystems.HFSPlus.CatalogFolderRecord
PowerForensics.FileSystems.HFSPlus.CatalogThread
PowerForensics.FileSystems.HFSPlus.ExtendedFileInfo
PowerForensics.FileSystems.HFSPlus.ExtendedFolderInfo
PowerForensics.FileSystems.HFSPlus.ExtentDescriptor
PowerForensics.FileSystems.HFSPlus.ExtentsOverflowFile
PowerForensics.FileSystems.HFSPlus.ExtentsOverflowRecord.FORK_TYPE
PowerForensics.FileSystems.HFSPlus.ExtentsOverflowRecord
PowerForensics.FileSystems.HFSPlus.FileInfo
PowerForensics.FileSystems.HFSPlus.FolderInfo
PowerForensics.FileSystems.HFSPlus.ForkData
PowerForensics.FileSystems.HFSPlus.Point
PowerForensics.FileSystems.HFSPlus.Rect
PowerForensics.FileSystems.HFSPlus.VolumeHeader.HFS_VERSION
PowerForensics.FileSystems.HFSPlus.VolumeHeader
PowerForensics.FileSystems.Ntfs.AttrDef.ATTR_DEF_ENTRY
PowerForensics.FileSystems.Ntfs.AttrDef
PowerForensics.FileSystems.Ntfs.AttributeList
PowerForensics.FileSystems.Ntfs.AttrRef
PowerForensics.FileSystems.Ntfs.ATTR_FILENAME_FLAG
PowerForensics.FileSystems.Ntfs.BadClus
PowerForensics.FileSystems.Ntfs.Bitmap
PowerForensics.FileSystems.Ntfs.Data
PowerForensics.FileSystems.Ntfs.DataRun
PowerForensics.FileSystems.Ntfs.EA
PowerForensics.FileSystems.Ntfs.EAInformation
PowerForensics.FileSystems.Ntfs.FileName
PowerForensics.FileSystems.Ntfs.FileRecord
PowerForensics.FileSystems.Ntfs.FileRecordAttribute.ATTR_TYPE
PowerForensics.FileSystems.Ntfs.FileRecordAttribute
PowerForensics.FileSystems.Ntfs.FILE_RECORD_FLAG
PowerForensics.FileSystems.Ntfs.IndexAllocation
PowerForensics.FileSystems.Ntfs.IndexAllocationTest
PowerForensics.FileSystems.Ntfs.IndexEntry
PowerForensics.FileSystems.Ntfs.IndexRoot
PowerForensics.FileSystems.Ntfs.INDEX_ROOT_FLAGS
PowerForensics.FileSystems.Ntfs.MasterFileTable
PowerForensics.FileSystems.Ntfs.NonResident
PowerForensics.FileSystems.Ntfs.NtfsVolumeBootRecord
PowerForensics.FileSystems.Ntfs.ObjectId
PowerForensics.FileSystems.Ntfs.StandardInformation.ATTR_STDINFO_PERMISSION
PowerForensics.FileSystems.Ntfs.StandardInformation
PowerForensics.FileSystems.Ntfs.UsnJrnl
PowerForensics.FileSystems.Ntfs.UsnJrnl.USN_REASON
PowerForensics.FileSystems.Ntfs.UsnJrnl.USN_SOURCE
PowerForensics.FileSystems.Ntfs.UsnJrnlInformation
PowerForensics.FileSystems.Ntfs.VolumeInformation.ATTR_VOLINFO
PowerForensics.FileSystems.Ntfs.VolumeInformation
PowerForensics.FileSystems.Ntfs.VolumeName
PowerForensics.FileSystems.VolumeBootRecord
PowerForensics.FileSystems.VolumeBootRecord.MEDIA_DESCRIPTOR
PowerForensics.Formats.ForensicTimeline.ACTIVITY_TYPE
PowerForensics.Formats.ForensicTimeline
PowerForensics.Formats.Gource
PowerForensics.Helper.FILE_SYSTEM_TYPE
PowerForensics.Helper
PowerForensics.Utilities.Compression.Xpress
PowerForensics.Utilities.DD
PowerForensics.Windows.Artifacts.AlternateDataStream
PowerForensics.Windows.Artifacts.ApacheAccessLog
PowerForensics.Windows.Artifacts.ApplicationCompatibilityCache.Amcache
PowerForensics.Windows.Artifacts.ApplicationCompatibilityCache.RecentFileCache
PowerForensics.Windows.Artifacts.ApplicationCompatibilityCache.Shimcache
PowerForensics.Windows.Artifacts.CommonNetworkRelativeLink.COMMON_NETWORK_RELATIVE_LINK_FLAGS
PowerForensics.Windows.Artifacts.CommonNetworkRelativeLink
PowerForensics.Windows.Artifacts.CommonNetworkRelativeLink.NETWORK_PROVIDER_TYPE
PowerForensics.Windows.Artifacts.ConsoleDataBlock.FILL
PowerForensics.Windows.Artifacts.ConsoleDataBlock.FONT
PowerForensics.Windows.Artifacts.ConsoleDataBlock
PowerForensics.Windows.Artifacts.ConsoleFeDataBlock
PowerForensics.Windows.Artifacts.DarwinDataBlock
PowerForensics.Windows.Artifacts.EnvironmentVariableDataBlock
PowerForensics.Windows.Artifacts.ExtraData.EXTRA_DATA_TYPE
PowerForensics.Windows.Artifacts.ExtraData
PowerForensics.Windows.Artifacts.IconEnvironmentDataBlock
Windows.Artifacts.IconEnvironmentDataBlock
Fields
PowerForensics.Windows.Artifacts.IdList
PowerForensics.Windows.Artifacts.ItemId
PowerForensics.Windows.Artifacts.JavaCache
PowerForensics.Windows.Artifacts.KnownFolderDataBlock
PowerForensics.Windows.Artifacts.MicrosoftOffice.FileMRU
PowerForensics.Windows.Artifacts.MicrosoftOffice.OutlookCatalog
PowerForensics.Windows.Artifacts.MicrosoftOffice.PlaceMRU
PowerForensics.Windows.Artifacts.MicrosoftOffice.TrustRecord
PowerForensics.Windows.Artifacts.Prefetch
PowerForensics.Windows.Artifacts.Prefetch.PREFETCH_ENABLED
PowerForensics.Windows.Artifacts.Prefetch.PREFETCH_VERSION
PowerForensics.Windows.Artifacts.PropertyStoreDataBlock
PowerForensics.Windows.Artifacts.RunKey
PowerForensics.Windows.Artifacts.SamHive.Sid
PowerForensics.Windows.Artifacts.SamHive.UserDetail
PowerForensics.Windows.Artifacts.ScheduledJob
PowerForensics.Windows.Artifacts.ScheduledJob.PRIORITY_CLASS
PowerForensics.Windows.Artifacts.ScheduledJob.PRODUCT_VERSION
PowerForensics.Windows.Artifacts.ScheduledJob.STATUS
PowerForensics.Windows.Artifacts.ScheduledJob.TASK_FLAG
PowerForensics.Windows.Artifacts.ScheduledTask
PowerForensics.Windows.Artifacts.ShellLink.FILEATTRIBUTE_FLAGS
PowerForensics.Windows.Artifacts.ShellLink.HOTKEY_FLAGS
PowerForensics.Windows.Artifacts.ShellLink.LINKINFO_FLAGS
PowerForensics.Windows.Artifacts.ShellLink.LINK_FLAGS
PowerForensics.Windows.Artifacts.ShellLink
PowerForensics.Windows.Artifacts.ShellLink.SHOWCOMMAND
PowerForensics.Windows.Artifacts.ShimDataBlock
PowerForensics.Windows.Artifacts.SoftwareHive.NetworkList
PowerForensics.Windows.Artifacts.SoftwareHive.WindowsVersion
PowerForensics.Windows.Artifacts.SpecialFolderDataBlock
PowerForensics.Windows.Artifacts.SystemHive.Timezone
PowerForensics.Windows.Artifacts.TrackerDataBlock
PowerForensics.Windows.Artifacts.UserHive.LastVisitedMRU
PowerForensics.Windows.Artifacts.UserHive.RecentDocs
PowerForensics.Windows.Artifacts.UserHive.RunMRU
PowerForensics.Windows.Artifacts.UserHive.TypedPaths
PowerForensics.Windows.Artifacts.UserHive.TypedUrls
PowerForensics.Windows.Artifacts.UserHive.UserAssist
PowerForensics.Windows.Artifacts.UserHive.WordWheelQuery
PowerForensics.Windows.Artifacts.VistaAndAboveIDListDataBlock
PowerForensics.Windows.Artifacts.VolumeId.DRIVE_TYPE
PowerForensics.Windows.Artifacts.VolumeId
PowerForensics.Windows.EventLog.BinaryXml
PowerForensics.Windows.EventLog.BinaryXml.TOKEN_TYPE
PowerForensics.Windows.EventLog.BinaryXml.VALUE_TYPE
PowerForensics.Windows.EventLog.BinXmlAttribute
PowerForensics.Windows.EventLog.BinXmlAttributeList
PowerForensics.Windows.EventLog.BinXmlName
PowerForensics.Windows.EventLog.BinXmlValueText
PowerForensics.Windows.EventLog.EventRecord
PowerForensics.Windows.EventLog.FILEFLAGS
PowerForensics.Windows.Registry.Cell
PowerForensics.Windows.Registry.HashedLeaf
PowerForensics.Windows.Registry.Leaf
PowerForensics.Windows.Registry.LeafItem
PowerForensics.Windows.Registry.List
PowerForensics.Windows.Registry.NamedKey
PowerForensics.Windows.Registry.NamedKey.NAMED_KEY_FLAGS
PowerForensics.Windows.Registry.OffsetRecord
PowerForensics.Windows.Registry.ReferenceItem
PowerForensics.Windows.Registry.RegistryHeader
PowerForensics.Windows.Registry.RegistryHelper
PowerForensics.Windows.Registry.SecurityDescriptor
PowerForensics.Windows.Registry.SecurityDescriptor.SECURITY_KEY_CONTROLS
PowerForensics.Windows.Registry.SecurityKey
PowerForensics.Windows.Registry.ValueKey
PowerForensics.Windows.Registry.ValueKey.VALUE_KEY_DATA_TYPES
PowerForensics.Windows.Registry.ValueKey.VALUE_KEY_FLAGS
About
License
PowerForensics
Docs
»
Development »
Public API »
PowerForensics.Windows.Artifacts.IconEnvironmentDataBlock
Edit on GitHub
Windows.Artifacts.IconEnvironmentDataBlock
Fields
TargetAnsi
TargetUnicode
Read the Docs