Daily Blog #561: Solution Saturday 12/8/18 - Battle of the Shims

Battle of the Shims - Winning answer to our most recent challenge by David Cowen - Hacking Exposed Computer Forensics Blog

Hello Reader,
       Another challenge where a new victor has emerged! One of the great things about these weekly challenges is that let's people within the larger community a chance to show what they got. This week Zach Stanford has made his mark with his winning submission.

The Challenge:

Document the order that the following shims are executed/data written in Windows 10:
  • Prefetch
  • Shimcache
  • Amcache
  • Userassist
  • SRUM
List the time stamps associated with the entry creation and whatever else you can determine about the order they are called

The Winning Answer:

