预取执行史析

原名:analyzing-prefetch-files-for-execution-history

解析 Windows Prefetch 文件(版本 17/23/26/30),利用 PECmd、WinPrefetchView 或 python-prefetch 等工具,获取程序执行历史、运行次数、时间戳及关联文件/DLL,用于构建执行时间线或调查取证。

分类
学习研究
版本
v1.0
作者
弈韬(@ra1nzzz)
下载
0
收藏
0
发布
2026-08-18
更新
2026-08-19
TRACE 评分
3.8 / 5

内容概览

- When determining which programs were executed on a Windows system and when - During malware investigations to confirm execution of suspicious binaries - For establishing a timeline of application usage during an incident - When correlating program execution with other forensic artifacts - To identify anti-forensic tools or unauthorized software that was run - Access to Windows Prefetch directory (C:\Windows\Prefetch\) from forensic image - PECmd (Eric Zimmerman), WinPrefetchView, or python-prefetch parser - Understanding of Prefetch file format (versions 17, 23, 26, 30) - Windows system with Prefetch enabled (default on client OS, disabled on servers) - Knowledge of Prefetch naming conventions (APPNAME-HASH.pf) Concept Description --------- ------------- Prefetch Windows performance optimization that pre-loads application data and tracks execution SCCA signature Magic bytes identifying…

查看 SKILL 详情