Hello Reader,
This week we have a clear winner with Maxim Suhanov not only answering the question but finding a new artifact and writing a proof of concept extractor for it in the process!
This week we have a clear winner with Maxim Suhanov not only answering the question but finding a new artifact and writing a proof of concept extractor for it in the process!
The Challenge:
On a Windows 7 system how long does it take for a new gui executable to appear in the Amcache. What can you do if anything to force the executable to appear in the amcache hive.
The Winning Answer:
Maxim Suhanov (@errno_fail)
You can read the answer here: https://dfir.ru/2018/12/02/the-cit-database-and-the-syscache-hive/
Also Read: Daily Blog #553
Post a Comment