ShimCache vs AmCache: Key Windows Forensic Artifacts: https://www.magnetforensics.com/blog/shimcache-vs-amcache-key-windows-forensic-artifacts/
ShimCache vs AmCache: Key Windows Forensic Artifacts: https://www.magnetforensics.com/blog/shimcache-vs-amcache-key-windows-forensic-artifacts/
Recently had an analysis where neither #amcache nor #shimcache showed an executable. However, the executable definitely ran.
Anyone knows when this happens? (might be connected: I'm not sure if the user was logged in interactively)
#DFIR folks, if you want to know (almost) everything about the #AmCache, I've just published a year worth of research, you can find it here: https://www.ssi.gouv.fr/en/publication/amcache-analysis/
@[email protected]
Feedbacks are very welcomed!
🐦🔗: https://twitter.com/moustik01/status/1087388584506736640