DFSP # 014 - Shimcache

DFSP # 014 - Shimcache

In this episode I talk Shimcache, otherwise known as the Application Compatibility Cache. This registry key has existed since Windows XP and tracks executable on a system, making it a great source of digital evidence for both disk forensics and incident response cases. In addition, there are freely available tools that will parse the data. It is not a difficult artifact to understand. Once an analyst spends the time learning how to pull, parse and interpret the data it is easily incorporated into an investigation and aligns well with other Windows artifacts.

Det här avsnittet är hämtat från ett öppet RSS-flöde och publiceras inte av Podme. Det kan innehålla reklam.

Avsnitt(498)

Populärt inom Vetenskap

p3-dystopia
dumma-manniskor
allt-du-velat-veta
medicinvetarna
rss-ufobortom-rimligt-tvivel
kapitalet-en-podd-om-ekonomi
rss-vetenskapsradion-2
rss-kriminologerna
rss-vetenskapsradion
svd-nyhetsartiklar
rss-spraket
sexet
bildningspodden
vetenskapsradion
rss-ronden
dumforklarat
rss-broccolipodden-en-podcast-som-inte-handlar-om-broccoli
rss-lara-fran-larda-en-fackbok-och-en-forfattare
rss-odla
naturmorgon