ShimCache/ AppCompatCache
HKLM\SYSTEM\CurrentControlSet\Control\SessionManager\AppCompanyCache\AppCompatCache
^ volatile key - look at 'SYSTEM\Select\Current' in offline systemParse:
AppCompatCache.exe -f .\SYSTEM --csv C:\Temp\# install
sudo apt install python2
curl https://bootstrap.pypa.io/pip/2.7/get-pip.py --output get-pip.py
sudo python2 get-pip.py
# import collected Amcache.hve and SYSTEM registry hives (can be multiple)
AppCompatProcessor.py ./database.db load /cases/precooked/appcompat/SRL_Shim_Amcache.zi
# search the DB
AppCompatProcessor.py ./database.db search
# Stack can be used to perform LFO (least frequency occurances)
AppCompatProcessor.py ./database.db stack "FilePath" "FileName LIKE '%svchost.exe'"
AppCompatProcessor.py ./database.db stack "FileName" "FilePath LIKE '%update'"
# Temporal Execution Correlation - look for similarity between malicious files
AppCompatProcessor.py ./database.db tcorr "edgeupdater.exe"
# Stack / Count file LFO (least frequency occurances)
AppCompatProcessor.py ./database.db stack "FileName" "length(filename)<8"
# Search for filename
AppCompatProcessor.py ./database.db fsearch FileName -f "arh.exe"
Last updated