logo

Hunting for Attacker’s Tactics and Techniques With Prefetch Files

ID: 7dbe4284-4e11-5dd2-90ba-28518a2e0899

STIX ID: report--7dbe4284-4e11-5dd2-90ba-28518a2e0899

Feed Name: Group-IB Blog

Date Published: 2019-12-11

Date Updated: 2026-04-27

...
...

This report explains how Windows Prefetch artifacts can be leveraged in DFIR to validate execution and uncover adversary tactics, techniques, and procedures by examining metadata such as run counts, timestamps, volume info, and especially the “Files Referenced” list. Using real-world examples mapped to MITRE ATT&CK (e.g., CHM via hh.exe T1223, CMSTP T1191, Regsvr32 T1117, Application Shimming via sdbinst T1138, PsExec/Windows Admin Shares T1077, and file deletion via SDelete T1107), it shows how Prefetch parsing (e.g., with PECmd) can reveal the specific scripts, databases, and payloads executed, supporting investigations across initial access, execution, persistence, lateral movement, and cleanup.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.