预取执行史析
原名:analyzing-prefetch-files-for-execution-history
解析 Windows Prefetch 文件(版本 17/23/26/30),利用 PECmd、WinPrefetchView 或 python-prefetch 等工具,获取程序执行历史、运行次数、时间戳及关联文件/DLL,用于构建执行时间线或调查取证。
- 分类
- 学习研究
- 版本
- v1.0
- 作者
- 弈韬(@ra1nzzz)
- 下载
- 0
- 收藏
- 0
- 发布
- 2026-08-18
- 更新
- 2026-08-19
- TRACE 评分
- 3.8 / 5
内容概览
- When determining which programs were executed on a Windows system and when - During malware investigations to confirm execution of suspicious binaries - For establishing a timeline of application usage during an incident - When correlating program execution with other forensic artifacts - To identify anti-forensic tools or unauthorized software that was run - Access to Windows Prefetch directory (C:\Windows\Prefetch\) from forensic image - PECmd (Eric Zimmerman), WinPrefetchView, or python-prefetch parser - Understanding of Prefetch file format (versions 17, 23, 26, 30) - Windows system with Prefetch enabled (default on client OS, disabled on servers) - Knowledge of Prefetch naming conventions (APPNAME-HASH.pf) Concept Description --------- ------------- Prefetch Windows performance optimization that pre-loads application data and tracks execution SCCA signature Magic bytes identifying…