Prefetch, AmCache, ShimCache in Windows
One of the most important artifact in digital forensic
Last updated
Was this helpful?
One of the most important artifact in digital forensic
Last updated
Was this helpful?
(Deep Dive on prefetch)
Prefetch is a software that was made by Microsoft -> To make better UX, but it is also being used in the DFIR field because the information it provided
Prefetch provides you with the time the file is executed, created, modified, deleted, and also how many times it execute
By the default you can't read prefetch using any text editor, you have to use a special tool call