DFSP # 014 - Shimcache

Digital Forensic Survival Podcast - En podcast af Digital Forensic Survival Podcast - Tirsdage

Kategorier:

In this episode I talk Shimcache, otherwise known as the Application Compatibility Cache. This registry key has existed since Windows XP and tracks executable on a system, making it a great source of digital evidence for both disk forensics and incident response cases. In addition, there are freely available tools that will parse the data. It is not a difficult artifact to understand. Once an analyst spends the time learning how to pull, parse and interpret the data it is easily incorporated into an investigation and aligns well with other Windows artifacts.  

Visit the podcast's native language site