Prefetch: The Little Snitch That Tells on You
ID: c41bafec-840b-51d5-ab9b-17e86668cacb
STIX ID: report--c41bafec-840b-51d5-ab9b-17e86668cacb
Feed Name: TrustedSec blog
This document explains Windows Prefetch files as a forensic artifact: how .pf files are created and named, what metadata they contain (creation time, run counts, referenced files/paths), and how analysts can use that data to identify malicious activity (examples include detecting file exfiltration via 7-Zip and DLL search-order hijacking). It also notes limitations (servers, SSDs, registry setting to enable/disable), and recommends tools such as Eric Zimmerman's PECmd and NirSoft's WinPrefetchView for extracting and analyzing prefetch data.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
