Site icon LIFARS, a SecurityScorecard company

Amcache and Shimcache Forensics

Amcache and Shimcache can be a powerful source of evidence to help expedite forensic investigations. These evidence can provide a timeline of which program was executed and when it was first run and last modified.

Forensic investigators can use these Amcache and Shimcache artifacts to find different types of information including but not limited to:

In this PDF, you will learn when and how to leverage Amcache and Shimcache artifacts in digital forensic cases.

Exit mobile version