logo

Forensic journey: Breaking down the UserAssist artifact structure

ID: 23dbfd17-3334-52e6-a4a8-03cb13e3fe5c

STIX ID: report--23dbfd17-3334-52e6-a4a8-03cb13e3fe5c

Feed Name: Securelist by Kaspersky

Date Published: 2025-07-14

Date Updated: 2026-04-29

Author: Awad Aljuaid

...
...

This report presents an in-depth forensic analysis of the Windows UserAssist artifact, explaining how shell32.dll logs GUI/CLI program executions, focus events, and durations, and why records often appear inconsistent. It reverse-engineers CUASession and the UEME_CTLSESSION value (including NMax “top usage” entries), documents the per-program binary structure with the newly identified r0 usage-percentage history and session reset logic, and provides practical insights for incident response along with a parser to extract these data points.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.