https://systw.net/note/archives/341
Win Forensics(NonVolatile)