Sveriges mest populära poddar

Digital Forensic Survival Podcast

DFSP # 014 - Shimcache

18 min • 23 maj 2016

In this episode I talk Shimcache, otherwise known as the Application Compatibility Cache. This registry key has existed since Windows XP and tracks executable on a system, making it a great source of digital evidence for both disk forensics and incident response cases. In addition, there are freely available tools that will parse the data. It is not a difficult artifact to understand. Once an analyst spends the time learning how to pull, parse and interpret the data it is easily incorporated into an investigation and aligns well with other Windows artifacts.

 
Förekommer på
00:00 -00:00