dissect.target icon indicating copy to clipboard operation
dissect.target copied to clipboard

Add Amcache Pca function

Open Zawadidone opened this issue 2 years ago • 2 comments

  • Review artefact new Windows 11 "execution" artefact in the PcaGeneralDb1.txt and/or PcaGeneralDb0.txt
  • Add function that parses the entries in these txt file(s)

References

Zawadidone avatar Jan 04 '23 21:01 Zawadidone

The PR #120 added the functionality to parse PcaGeneralDb0.txt. The following additional files could also be added to the applaunch record and function:

PcaGeneralDb0.txt

2022-12-19 17:57:45.865|2|%programfiles%\freefilesync\freefilesync.exe|freefilesync|freefilesync.org|11.28|000633a92018be9965dd4f5fbff878d2c1cc00000904|Abnormal process exit with code 0x2

  • Timestamp
  • Application name
  • Software vendor
  • File version
  • Program ID (not a hash)
  • Exit message

Zawadidone avatar Jan 18 '23 09:01 Zawadidone

Yeah I kept this issue open for that reason :)

Schamper avatar Jan 18 '23 10:01 Schamper