C:\Unattend.xml
C:\Windows\Panther\Unattend.xml
C:\Windows\Panther\Unattend\Unattend.xml
C:\Windows\system32\sysprep.inf
C:\Windows\system32\sysprep\sysprep.xml
%userprofile%\AppData\Roaming\Microsoft\Windows\PowerShell\PSReadline\ConsoleHost_history.txt
C:\Users\<your_username>\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp
C:\Windows\SYSVOL\sysvol\
C:\Windows\NTDS\ntds.dit
C:\Windows\System32\config\SYSTEM
C:\Windows\System32\config\SECURITY
c:\Windows\System32\config\sam
\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy1\windows\system32\config\sam
Key decryption:
c:\Windows\System32\Config\system
\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy1\windows\system32\config\system
C:\Program Files\LAPS\CSE
C:\inetpub\wwwroot\web.config
C:\Windows\Microsoft.NET\Framework64\<version>\Config\web.config
C:\inetpub\wwwroot
c:\Windows\Microsoft.NET\Framework\<version>\MSBuild.exe
The plain-text credentials existed on EC2 instance.
%UserProfile%\.aws\credentials
$HOME/.aws/credentials