appcompatprocessor
appcompatprocessor copied to clipboard
"Evolving AppCompat/AmCache data analysis beyond grep"
Add a comment that it seems to work OK on Windows Subsystem for Linux (WSL) on Windows 10.
Hi Matias, Do you have plan to add the parsing and analysis for the syscache.hve. You can look into David Cowen research below https://www.hecfblog.com/2018/12/daily-blog-573-forensic-lunch-test.html?m=1
On hold: https://github.com/mandiant/ShimCacheParser/issues/20
Hi guys, Amcache parser did not works because of the new structure. Can you update the parser ? Regards
Feature Request: Import raw .REG key values... They're easy to collect with PowerShell and faster than trying to get the entire SYSTEM hives.