解析Amcache痕迹

原名:analyzing-windows-amcache-artifacts

使用 Eric Zimmerman 的工具解析 Windows Amcache.hve 注册表配置单元。

分类
开发提效
版本
v1.0.0
作者
弈韬(@ra1nzzz)
下载
1
收藏
0
发布
2026-08-18
更新
2026-08-20
TRACE 评分
3.4 / 5

内容概览

- Determining which programs have existed or executed on a Windows system during incident response - Correlating SHA-1 hashes from Amcache against known malware databases (VirusTotal, CIRCL, MISP) - Building an application installation and execution timeline for forensic investigations - Identifying deleted executables that leave traces in Amcache even after file removal - Investigating insider threats by documenting which portable or unauthorized applications were present - Analyzing driver loading history to detect rootkits or malicious kernel modules Do not use as sole proof of program execution. Amcache proves file existence and metadata registration, but ShimCache (AppCompatCache) and Prefetch provide stronger execution evidence. Use all three artifacts together for conclusive analysis. - A forensic image or live triage copy of C:\Windows\appcompat\Programs\Amcache.hve (and associat…

查看 SKILL 详情