Windows 11 has introduced several significant changes that impact both enterprise security and digital forensics, particularly as organizations prepare for the end of Windows 10 support in October 2025. Despite Windows 11 being available for several years, enterprise adoption has lagged, with many organizations still relying on Windows 10 and even Windows 7, according to data from Kaspersky’s Global Emergency Response Team. As Windows 10 reaches end-of-life, a shift toward Windows 11 is expected, which will bring new challenges and opportunities for incident response teams. One of the most notable new features in Windows 11 is Recall, an AI-powered tool that continuously takes screenshots of the user’s display, analyzes them locally, and stores extracted information in a searchable database. This feature, available broadly since May 2025 on ARM-based systems with dedicated NPUs, has sparked controversy due to its privacy implications and the potential forensic value of its artifacts. Recall’s database could provide investigators with a detailed timeline of user activity, but it also raises concerns about the security and retention of sensitive information. In parallel, Microsoft has expanded the capabilities of Copilot, its AI assistant, within Windows 11. Copilot can now link to both Microsoft and Google accounts, allowing users to access files, emails, and calendar data from services like OneDrive, Outlook, Google Drive, Gmail, and Google Calendar directly through the Windows interface. This integration, currently available to Windows 11 Insiders, enables users to query Copilot for specific information across multiple platforms, such as retrieving contact details or locating recent documents. The process involves connecting accounts through the Copilot app’s settings, after which the AI can search and retrieve data as requested. These advancements in AI-driven features not only enhance user productivity but also introduce new vectors for data exposure and complicate the forensic landscape. Security professionals must now account for the presence of AI-generated artifacts and the expanded data access capabilities when conducting investigations or assessing organizational risk. The combination of Recall’s comprehensive activity logging and Copilot’s cross-platform data access underscores the need for updated security policies and forensic methodologies tailored to Windows 11’s evolving ecosystem. As organizations transition to Windows 11, understanding these features and their implications will be critical for maintaining robust security postures and effective incident response.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Securelist published research on Windows 11 forensic artifacts in the context of Windows 10 reaching end of life. The reference indicates a technical analysis release rather than a discrete security incident.
ZDNET published an article describing a practical test of Copilot against the author's Microsoft and Google accounts and reporting the observed results. The reference does not provide additional incident details beyond the publication itself.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
zdnet.com
Open sourcedoublepulsar.com
Open sourcesecurelist.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.