Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17


Does Windows 7 log all files every opened?

Posted on 2011-09-02
Medium Priority
Last Modified: 2012-05-12

Im trying to find out whether windows retains a log of all files ever opened and what location is was launched from.

Question by:daiwhyte
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
LVL 21

Accepted Solution

netcmh earned 501 total points
ID: 36473741
Opening a file is a vague term. Applications and users "open" files differently.

Are you trying to get a log of user actions on a commonly shared file/s or folder/s? If so, then a versioning software might be the answer.

Since, the OS log files can only grow up to a limit, they tend to overwrite the oldest data. Not sure how long back you wanted to go.

Assisted Solution

ChopOMatic earned 501 total points
ID: 36473859
Unfortunately, the answer is no. There is a journal (USNJRNL) that maintains a record of file changes, but no system process that logs every open. Any such log would be prohibitively cumbersome to maintain IMHO. To see what I mean, download and run FILEMON. This will let you view file activity on your system in real time. Watch it for a few minutes, then imagine that a process like that is running 100% of the time and documenting that activity.
LVL 65

Assisted Solution

btan earned 498 total points
ID: 36477141
Windows 7 does not keep the copy of the files ever opened.

Even at audit policy level [1], it goes as far as to just tracking all the files that are accessed by defined groups of (local/domain) users or even to per user audit trail. The event are captured provided the policy are enabled prior to those activities.

Windows has Shadow Copy (Volume Snapshot Service or Volume Shadow Copy Service or VSS) [2] which is a technology included in Microsoft Windows that allows taking manual or automatic backup copies or snapshots of data, even if it has a lock, on a specific volume at a specific point in time over regular intervals. The end result is similar to a versioning file system, allowing any file to be retrieved as it existed at the time any of the snapshots was made. But it is not necessarily triggered when document is opened. E.g. The shadow copy is not created every time a file is changed; backup copies are created automatically once per day, or manually when triggered by the backup utility or installer applications which create a restore point. For program installed, there is always a snapshot capture of the machine state, or they sometime called it restore point created.

There is possibility to track temp files but not necessary the copy of the final file. It is dependent on the application use to open the files. E.g For microsoft office, one of the possible area is stored in the Temp folder and there may be more [3]. The recently open file are also tracked by office [4]. Interesting for outlook attachment, there can be log of it too [5].

Overall, unless using third party product monitoring the file or you are setting up honeypot, it depends mostly on the application as well.
The logging of file is space eater hence probably tracking and logging the event may suffice. Just some thoughts


Author Closing Comment

ID: 36488458
Thank you.

Featured Post

Free Tool: ZipGrep

ZipGrep is a utility that can list and search zip (.war, .ear, .jar, etc) archives for text patterns, without the need to extract the archive's contents.

One of a set of tools we're offering as a way to say thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

The foremost challenge encountered by an investigator at the very beginning of a forensics investigation is, accessing a file/data to read/view its contents. Owing to the fact, a platform is necessary for both; opening as well as examining any file.…
In this era, as you know, cybercrime and other sorts of frauds using the internet has increased day by day. We should protect our information assets and confidential information from getting exploiting by the attacker or intruders. Most of the fraud…
Video by: ITPro.TV
In this episode Don builds upon the troubleshooting techniques by demonstrating how to properly monitor a vSphere deployment to detect problems before they occur. He begins the show using tools found within the vSphere suite as ends the show demonst…
Do you want to know how to make a graph with Microsoft Access? First, create a query with the data for the chart. Then make a blank form and add a chart control. This video also shows how to change what data is displayed on the graph as well as form…

664 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question