Shimcache Execution Is Back - What You Need to Know!
Автор: 13Cubed
Загружено: 2024-09-06
Просмотров: 4260
Описание:
In this special episode, Mike Peterson from nullsec.us joins us to discuss important new research on Shimcache/AppCompatCache. Discover how this artifact can potentially be used to prove execution in Windows 10 and later—a capability that was previously thought impossible!
** If you enjoy this video, please consider supporting 13Cubed on Patreon at patreon.com/13cubed. **
📖 Chapters
00:00 - Intro
01:08 - Shimcache/AppCompatCache artiFACTS
09:38 - nullsec.us Research
18:40 - Wrap-up
🛠 Resources
Original research from Eric Zimmerman:
https://github.com/EricZimmerman/AppC...
GitHub commit for AppCompatCacheParser adding the functionality (March 2023):
https://github.com/EricZimmerman/AppC...
For even more in-depth information, please refer to this multipart blog series:
https://nullsec.us/windows-10-11-appc...
https://nullsec.us/building-appcompat...
https://nullsec.us/appcompatcache-par...
#Forensics #DigitalForensics #DFIR #ComputerForensics #WindowsForensics
Повторяем попытку...
Доступные форматы для скачивания:
Скачать видео
-
Информация по загрузке: