Professional Documents
Culture Documents
Def: key processs in which the operating system loads key pieces of data and code
from disk into memory
. pf name: name of application + hex representation of the file path
Disable/enable: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control
\Session Manager\Memory Management\PrefetchParameters
limit to 128 files on W7 en 1024 files on W8 and above it will log the entry for the command the person executed
PECmd: free tool designed to parse the internal metadata of prefetch files
relies upon W API so will only work with W8+ C:\%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Recent\
-d switch: will process entire dir + will create a timeline
AutomaticDestinations
- Creation time (first exec): first time item added to the appID file
Def: Application Compatibility cache is designed to detect and remediate program - Last time of exec: modification time = last time item added to the AppID file
compatibility challenges when a program launches. Microsoft allows a program to - list of jump list IDs can be found at: http://www.forensicswiki.org/wiki/
invoke properties of different operating system versions. The different compatibility Jump Lists
List_of_Jump_List_IDs
modes are called "Shims".
Shims: the different compatibility modes A jump list is a system-provided menu that appears when the user right-clicks a
AppCompatCache: each exec is checked and added to the registry regardless of program in the taskbar or on the Start menu. It is used to provide quick access to
whether it needs to be shimmed Program recently or frequently-used documents and offer direct links to app functionality. For
example, when you right click on Chrome.exe, you see tabs/urls that you recently
- Filename
Execusion closed. That information has to be safed somewhere...
- full path
- last modification time of the exec
Location running system:
Max 512 entries HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
\ComDlg32\LastVisitedMRU
Location: (hives in Windows\config) ShimCache / AppCompatCache
New entries only written on shutdown
SYSTEM\CurrentControlSet\Control\SessionManager\AppCompatCache Offline system: Registry Explorer
Might see multiple CurrentControlSet keys: in offline system, you first need to \AppCampotCache NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Explorer
determine the current control set by looking at the Current value in the SYSTEM \ComDlg32\LastVisitedMRU
\Select key Last Visited MRU
MRUListEx: records the order in which the files were accessed (as a 4-byte value)
AppCompatCacheParser.exe: For example: 07 00 00 00 00 00 00 00 04 00 00 00 0E 00 00 00 -> means that last
-f switch: if not set, appcompatcache of running system will be taken value 7 downloaded, than 0,4 and last value 14
- Full path
- file size
- publisher metadata
- several timestamps
amcacheparser.exe
-i switch: gives associated files
- Amcache_ProgramEntries folder: will contain the InventoryApplication key
- UnassociatedFileEntries: part of the InventoryApplicationFile key that contains files
that are not part of an installation package.
appcompatprocessor.py (p.2.64)