If a mischief administrator has turned off a server using putty (SSH) and post which he/she deleted the putty. Forensics needs to be performed for the same admin system image.
How come an investigator will come to know about putty.
Its ok if investigator came to know via deleted files.
Now How he can make sure that Putty was ran against that server and post which which all activities have been performed using putty.
NOTE: Putty was not installed and it was run portably.