Memory analysis
Timestamps in Thread and Process Objects
(Dieser Artikel ist auch auf Deutsch verfügbar.)
The Windows kernel creates a distinct object for every process and every thread in its memory. It is possible to extract these blocks of data from memory images. At this even the remnants of terminated processes and threads can be found. Among their status information there are several timestamps.