appcompatprocessor icon indicating copy to clipboard operation
appcompatprocessor copied to clipboard

"Evolving AppCompat/AmCache data analysis beyond grep"

Results 6 appcompatprocessor issues
Sort by recently updated
recently updated
newest added

Add a comment that it seems to work OK on Windows Subsystem for Linux (WSL) on Windows 10.

Hi Matias, Do you have plan to add the parsing and analysis for the syscache.hve. You can look into David Cowen research below https://www.hecfblog.com/2018/12/daily-blog-573-forensic-lunch-test.html?m=1

enhancement

On hold: https://github.com/mandiant/ShimCacheParser/issues/20

Hi guys, Amcache parser did not works because of the new structure. Can you update the parser ? Regards

Feature Request: Import raw .REG key values... They're easy to collect with PowerShell and faster than trying to get the entire SYSTEM hives.

enhancement