The process of extracting 360 antivirus software history log forensic analysis of the public security agencies to characterize the behavior of suspects is of great significance. Elaborated on how to use 360 anti-virus software process history log accurately analyze the user’s behavior to obtain evidence. Through 360 anti-virus software history process log can restore the Office file editing process time node, the computer system switch machine records and the user process running status, so as to extract the suspect behavior characteristics related to the clues.