This document discusses investigating Windows systems through computer forensics. It outlines how to locate user data in profiles and folders, as well as system artifacts generated by the operating system, such as metadata, the registry, event logs, swap files, and the recycle bin. Default locations are provided for where to find this information on Windows systems to most efficiently search large amounts of data during an investigation.