pjrinaldi / wombatforensics

linux c++, fox-toolkit, multi-threaded forensic gui tool
GNU General Public License v2.0
47 stars 12 forks source link

Prefetch Parser #319

Closed pjrinaldi closed 1 year ago

pjrinaldi commented 4 years ago

Implement a parser/viewer for prefetch files.

Should be able to pull in libscca to do the heavy lifting.

pjrinaldi commented 4 years ago

prefetch should be working for winxp, vista, 7, 8, 8.1, and early 10. started on compressed 10 version. tested xp and 7. need samples to test others.

pjrinaldi commented 4 years ago

Prefetch is working for all os versions. will open a new ticket if any new issues crop up.

pjrinaldi commented 1 year ago

started on prefetch parser. Got MAM uncompressed to a regular prefetch and will implement parsing next.

pjrinaldi commented 1 year ago

prefetch is working. will open new tickets if any issues arise while testing.