[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$ftb7oNw6HE0_ENXNHS_SxUzZkoY_HHHoXBNO99YuR1XU":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":52,"createdAt":52,"_status":51},318,"How can attackers clear file execution records from the Windows registry without leaving traces?","To clear ShimCache records, an attacker can export the registry key before a system reboot and reimport it afterward, as ShimCache only updates on reboot. Alternatively, an abnormal shutdown can skip the registry write operation. For UserAssist, MUICache, RunMRU, and AppCompatFlags, attackers can simply delete the corresponding registry key values. However, these operations may themselves be logged. For stealthier approaches, consider techniques described in [Penetration Techniques - Stealth Execution of Windows Remote Assistance](\u002Fnews\u002Fpenetration-techniques-stealth-execution-of-windows-remote-assistance) or [Penetration Techniques - Deletion and Bypass of Windows Logs](\u002Fnews\u002Fpenetration-techniques-deletion-and-bypass-of-windows-logs).","\u003Cp>To clear ShimCache records, an attacker can export the registry key before a system reboot and reimport it afterward, as ShimCache only updates on reboot. Alternatively, an abnormal shutdown can skip the registry write operation. For UserAssist, MUICache, RunMRU, and AppCompatFlags, attackers can simply delete the corresponding registry key values. However, these operations may themselves be logged. For stealthier approaches, consider techniques described in [Penetration Techniques - Stealth Execution of Windows Remote Assistance](\u002Fnews\u002Fpenetration-techniques-stealth-execution-of-windows-remote-assistance) or [Penetration Techniques - Deletion and Bypass of Windows Logs](\u002Fnews\u002Fpenetration-techniques-deletion-and-bypass-of-windows-logs).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fpenetration-techniques-acquisition-and-clearing-of-windows-system-file-execution-records\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-can-attackers-clear-file-execution-records-from-the-windows-registry-without-1777484214799","clearing records, registry manipulation, ShimCache reboot, abnormal shutdown, UserAssist deletion, stealth execution",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":48,"updatedAt":49,"createdAt":50,"_status":51},81,"Penetration Techniques - Acquisition and Clearing of Windows System File Execution Records","penetration-techniques-acquisition-and-clearing-of-windows-system-file-execution-records","Learn how to acquire and clear Windows file execution records from logs, registry, and files for penetration testing and defense. Covers ShimCache, event logs, and exploitation methods.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>From a penetration perspective, after gaining access to a Windows host, it is necessary to fully understand the information of this Windows host, and file execution records are an important part.\u003C\u002Fp>\u003Cp>From a defense perspective, file execution records contain important system information, and it is necessary to specifically clear them.\u003C\u002Fp>\u003Cp>Therefore, this article will attempt to organize the common locations of file execution records on Windows hosts (Win7 and above systems), try to acquire and clear individual records, analyze exploitation ideas, and summarize defense methods.\u003C\u002Fp>\u003Cp>Reference links:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fblog.1234n6.com\u002F2018\u002F10\u002Favailable-artifacts-evidence-of.html?m=1\u003C\u002Fp>\u003Cp>https:\u002F\u002Fxz.aliyun.com\u002Ft\u002F3067#toc-5\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Obtaining file execution records from logs\u003C\u002Fli>\u003Cli>Obtaining file execution records from the registry\u003C\u002Fli>\u003Cli>Obtaining file execution records from files\u003C\u002Fli>\u003Cli>Instance Testing\u003C\u002Fli>\u003Cli>Exploitation and Defense Strategies\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Obtaining File Execution Records from Logs\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Process Creation (ID: 4688)\u003C\u002Fh3>\u003Cp>Usage Conditions:\u003C\u002Fp>\u003Cp>This feature is disabled by default in the system and requires manual configuration to enable\u003C\u002Fp>\u003Cp>Policy location: Computer Configuration -&gt; Policies -&gt; Windows Settings -&gt; Security Settings -&gt; Advanced Audit Configuration -&gt; Detailed Tracking\u003C\u002Fp>\u003Cp>Policy Name: Audit Process Creation\u003C\u002Fp>\u003Cp>Command line to retrieve log information:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wevtutil qe security \u002Frd:true \u002Ff:text \u002Fq:\"Event[System[(EventID=4688)]]\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>Methods to clear records:\u003C\u002Fh4>\u003Cp>For clearing individual log entries, refer to the previous article:\u003C\u002Fp>\u003Cp>\"Penetration Techniques – Deleting Single Windows Log Entries\"\u003C\u002Fp>\u003Ch3>2. Microsoft-Windows-Application-Experience Program-Inventory\u003C\u002Fh3>\u003Cp>References:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fjourneyintoir.blogspot.com\u002F2014\u002F03\u002Fexploring-program-inventory-event-log.html\u003C\u002Fp>\u003Cul>\u003Cli>800 (summary of software activities)\u003C\u002Fli>\u003Cli>903 &amp; 904 (new application installation)\u003C\u002Fli>\u003Cli>905 &amp; 906 (updated application)\u003C\u002Fli>\u003Cli>907 &amp; 908 (removed application).\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Command line to obtain log information:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wevtutil qe Microsoft-Windows-Application-Experience\u002FProgram-Inventory\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>3、Microsoft-Windows-Application-Experience Program-Telemetry\u003C\u002Fh3>\u003Cp>Command line to obtain log information:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wevtutil qe Microsoft-Windows-Application-Experience\u002FProgram-Telemetry\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x03 Obtain file execution records from the registry\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1、ShimCache\u003C\u002Fh3>\u003Cp>References:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.fireeye.com\u002Fblog\u002Fthreat-research\u002F2015\u002F06\u002Fcaching_out_the_val.html\u003C\u002Fp>\u003Cp>Used to record compatibility issues generated during the execution of Windows system programs\u003C\u002Fp>\u003Cp>Location:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Session Manager\\AppCompatCache\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>XP stores up to 96 records, Windows 7 and above store up to 1024 records\u003C\u002Fp>\u003Cp>Records the following content:\u003C\u002Fp>\u003Cul>\u003Cli>File path\u003C\u002Fli>\u003Cli>Last modified time\u003C\u002Fli>\u003Cli>Whether it was executed\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>ShimCache not only records the execution of exe files but also records files in the same directory as the exe file (if the file was not executed, the Executed attribute is no)\u003C\u002Fp>\u003Cp>Data is saved in a fixed format, storage structure can be referenced at:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.fireeye.com\u002Fcontent\u002Fdam\u002Ffireeye-www\u002Fservices\u002Ffreeware\u002Fshimcache-whitepaper.pdf\u003C\u002Fp>\u003Ch4>Parsing tools\u003C\u002Fh4>\u003Cp>(1)\u003C\u002Fp>\u003Cp>Open source code (C#)\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FEricZimmerman\u002FAppCompatCacheParser\u002F\u003C\u002Fp>\u003Cp>Usage example:\u003C\u002Fp>\u003Cp>Read the current system's registry and output the results to a specified path:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>AppCompatCacheParser.exe --csv c:\\test\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Output results sorted by last modified time:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>AppCompatCacheParser.exe --csv c:\\test -t\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Read a specified System file and output the results to a specified path:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>AppCompatCacheParser.exe --csv c:\\test -h C:\\Windows\\System32\\config\\SYSTEM\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(2)\u003C\u002Fp>\u003Cp>Open source code (Python)\u003C\u002Fp>\u003Cp>If you want to first export the registry file and then obtain parsing results in another system, you can use a Python-implemented script:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fmandiant\u002FShimCacheParser\u003C\u002Fp>\u003Cp>Usage example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg export \"HKLM\\SYSTEM\\CurrentControlSet\\Control\\Session Manager\\AppCompatCache\" ShimCache.reg\u003Cbr>ShimCacheParser.py -o out.csv -r c:\\test\\ShimCache.reg -t\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Export results via System file:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ShimCacheParser.py -o out.csv -i C:\\Windows\\System32\\config\\SYSTEM -t\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>Methods to clear records\u003C\u002Fh4>\u003Cp>ShimCache only updates after system reboot (logging off current user does not update it)\u003C\u002Fp>\u003Cp>That is to say, there are two methods to clear ShimCache records from the current system startup to shutdown:\u003C\u002Fp>\u003Cp>(1) Modify the registry\u003C\u002Fp>\u003Cp>Backup current registry:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg export \"HKLM\\SYSTEM\\CurrentControlSet\\Control\\Session Manager\\AppCompatCache\" ShimCache.reg\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>After system reboot, restore registry:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg import ShimCache.reg\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(2) Abnormal shutdown\u003C\u002Fp>\u003Cp>Skip the registry write operation, preventing recording of this system's startup-to-shutdown activity\u003C\u002Fp>\u003Cp>(3) Modify memory\u003C\u002Fp>\u003Cp>(Theoretically feasible)\u003C\u002Fp>\u003Ch3>2、UserAssist\u003C\u002Fh3>\u003Cp>Reference:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.4n6k.com\u002F2013\u002F05\u002Fuserassist-forensics-timelines.html\u003C\u002Fp>\u003Cp>Can be used to record the number of executions and the last execution time of Windows system programs\u003C\u002Fp>\u003Cp>Location:\u003C\u002Fp>\u003Cp>Current User:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>All Users:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>HKEY_USERS\\\u003Csid>\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\u003C\u002Fsid>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Subkey names are encrypted using ROT-13 (decryption is relatively simple)\u003C\u002Fp>\u003Cp>Records update in real-time\u003C\u002Fp>\u003Ch4>Parsing Tools\u003C\u002Fh4>\u003Cp>(1)\u003C\u002Fp>\u003Cp>Command-line parsing\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.nirsoft.net\u002Futils\u002Fuserassist_view.html\u003C\u002Fp>\u003Cp>Usage example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>UserAssistView.exe \u002Fstext out.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(2)\u003C\u002Fp>\u003Cp>Open source code (C#)\u003C\u002Fp>\u003Cp>https:\u002F\u002Fblog.didierstevens.com\u002Fprograms\u002Fuserassist\u002F\u003C\u002Fp>\u003Ch4>Method to clear records\u003C\u002Fh4>\u003Cp>Clear corresponding registry key values\u003C\u002Fp>\u003Ch3>3. MUICache\u003C\u002Fh3>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwhat-when-how.com\u002Fwindows-forensic-analysis\u002Fregistry-analysis-windows-forensic-analysis-part-8\u002F\u003C\u002Fp>\u003Cp>Used to record the file names of exe files, storing the absolute path of exe files and the corresponding exe file names in the registry\u003C\u002Fp>\u003Cp>Location:\u003C\u002Fp>\u003Cp>Current user:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\Software\\Microsoft\\Windows\\Shell\\MuiCache\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>All users:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>HKEY_USERS\\\u003Csid>\\Software\\Classes\\Local Settings\\Software\\Microsoft\\Windows\\Shell\\MuiCache\u003C\u002Fsid>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Data not encrypted\u003C\u002Fp>\u003Cp>Records updated in real-time\u003C\u002Fp>\u003Ch4>Parsing tool\u003C\u002Fh4>\u003Cp>(1)\u003C\u002Fp>\u003Cp>Command-line parsing\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.nirsoft.net\u002Futils\u002Fmuicache_view.html\u003C\u002Fp>\u003Cp>Usage example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>MUICacheView.exe \u002Fstext out.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(2) Direct registry query\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg query \"HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\Software\\Microsoft\\Windows\\Shell\\MuiCache\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>Method to clear records\u003C\u002Fh4>\u003Cp>Clear corresponding registry key values\u003C\u002Fp>\u003Ch3>4、RunMRU\u003C\u002Fh3>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.forensicfocus.com\u002Fa-forensic-analysis-of-the-windows-registry\u003C\u002Fp>\u003Cp>Stores the history of programs launched via Win+U\u003C\u002Fp>\u003Cp>Location:\u003C\u002Fp>\u003Cp>Current User:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\RunMRU\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>All Users:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>HKEY_USERS\\\u003Csid>\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\RunMRU\u003C\u002Fsid>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Data is not encrypted\u003C\u002Fp>\u003Cp>Records update in real-time\u003C\u002Fp>\u003Ch4>Parsing tools\u003C\u002Fh4>\u003Cp>(1) Directly query the registry\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg query \"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\RunMRU\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>Methods to clear records\u003C\u002Fh4>\u003Cp>Delete the corresponding registry key values\u003C\u002Fp>\u003Ch3>5. AppCompatFlags Registry Keys\u003C\u002Fh3>\u003Cp>References:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fjourneyintoir.blogspot.com\u002F2013\u002F12\u002Frevealing-program-compatibility.html\u003C\u002Fp>\u003Cp>Save program execution records\u003C\u002Fp>\u003Cp>Location:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>HKLM\\Software\\Microsoft\\Windows NT\\CurrentVersion\\AppCompatFlags\\Layers\u003Cbr>HKCU\\Software\\Microsoft\\Windows NT\\CurrentVersion\\AppCompatFlags\\Layers\u003Cbr>HKCU\\Software\\Microsoft\\Windows NT\\CurrentVersion\\AppCompatFlags\\Compatibility Assistant\\Persisted\u003Cbr>HKCU\\Software\\Microsoft\\Windows NT\\CurrentVersion\\AppCompatFlags\\Compatibility Assistant\\Store\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>Parsing tools\u003C\u002Fh4>\u003Cp>(1) Direct registry query\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg query \"HKLM\\Software\\Microsoft\\Windows NT\\CurrentVersion\\AppCompatFlags\\Layers\"\u003Cbr>reg query \"HKCU\\Software\\Microsoft\\Windows NT\\CurrentVersion\\AppCompatFlags\\Layers\"\u003Cbr>reg query \"HKCU\\Software\\Microsoft\\Windows NT\\CurrentVersion\\AppCompatFlags\\Compatibility Assistant\\Persisted\"\u003Cbr>reg query \"HKCU\\Software\\Microsoft\\Windows NT\\CurrentVersion\\AppCompatFlags\\Compatibility Assistant\\Store\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>Methods to clear records\u003C\u002Fh4>\u003Cp>Clear the corresponding registry key values\u003C\u002Fp>\u003Ch2>0x04 Obtain file execution records from files\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1、Prefetch\u003C\u002Fh3>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.forensicmag.com\u002Farticle\u002F2010\u002F12\u002Fdecoding-prefetch-files-forensic-purposes-part-1\u003C\u002Fp>\u003Cp>Prefetch folder, used to store prefetch information for files that the system has accessed, which can speed up system startup\u003C\u002Fp>\u003Cp>Records the number of times a file has been run, last execution time, Hash, etc.\u003C\u002Fp>\u003Cp>Check if this feature is enabled:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg query \"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Session Manager\\Memory Management\\PrefetchParameters\" \u002Fv EnablePrefetcher\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cul>\u003Cli>0 = Disabled\u003C\u002Fli>\u003Cli>1 = Only Application launch prefetching enabled\u003C\u002Fli>\u003Cli>2 = Only Boot prefetching enabled\u003C\u002Fli>\u003Cli>3 = Both Application launch and Boot prefetching enabled\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Location:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>C:\\Windows\\Prefetch\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Data is saved in a fixed format with the extension .pf\u003C\u002Fp>\u003Ch4>Parsing tool\u003C\u002Fh4>\u003Cp>(1)\u003C\u002Fp>\u003Cp>Command-line parsing\u003C\u002Fp>\u003Cp>Open-source code (C#)\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FEricZimmerman\u002FPECmd\u003C\u002Fp>\u003Cp>Usage example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>PECmd.exe -d C:\\Windows\\Prefetch --csv c:\\temp\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Generates two files: \"time\"_PECmd_Output.csv and \"time\"_PECmd_Output_Timeline.csv\u003C\u002Fp>\u003Cp>\"time\"_PECmd_Output.csv stores detailed information\u003C\u002Fp>\u003Cp>\"time\"_PECmd_Output_Timeline.csv only stores a list of file names\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>PECmd.exe -d C:\\Windows\\Prefetch --json c:\\temp\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Generates multiple JSON files, each corresponding to one .pf file\u003C\u002Fp>\u003Ch4>Method to clear records\u003C\u002Fh4>\u003Cp>Delete the corresponding .pf file by filename\u003C\u002Fp>\u003Ch3>2. Amcache\u003C\u002Fh3>\u003Cp>References:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fjourneyintoir.blogspot.com\u002F2013\u002F12\u002Frevealing-recentfilecachebcf-file.html\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.swiftforensics.com\u002F2013\u002F12\u002Famcachehve-in-windows-8-goldmine-for.html\u003C\u002Fp>\u003Cp>Used to track application compatibility issues with different executable files\u003C\u002Fp>\u003Cp>Data is saved in a fixed format\u003C\u002Fp>\u003Cp>Location:\u003C\u002Fp>\u003Cp>Windows 7:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>C:\\Windows\\AppCompat\\Programs\\RecentFileCache.bcf\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Only records file names\u003C\u002Fp>\u003Cp>Windows 8 and above:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>C:\\Windows\\AppCompat\\Programs\\Amcache.hve\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Records creation time, last modification time, SHA1, and some PE file header information\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>After installing KB2952664 on Win7 systems, Amcache.hve will also be supported, meaning both RecentFileCache.bcf and Amcache.hve contain file execution records\u003C\u002Fp>\u003Ch4>Parsing tool (RecentFileCache.bcf)\u003C\u002Fh4>\u003Cp>(1)\u003C\u002Fp>\u003Cp>Open source code (C#)\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fjwhwan9\u002FdumpBCF\u003C\u002Fp>\u003Cp>(2)\u003C\u002Fp>\u003Cp>Open source code (Python)\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fprolsen\u002Frecentfilecache-parser\u003C\u002Fp>\u003Cp>Usage example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>rfcparse.py -f C:\\Windows\\AppCompat\\Programs\\RecentFileCache.bcf\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>Parsing tool (Amcache.hve)\u003C\u002Fh4>\u003Cp>(1)\u003C\u002Fp>\u003Cp>Command-line parsing\u003C\u002Fp>\u003Cp>Open source code (C#)\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FEricZimmerman\u002FAmcacheParser\u003C\u002Fp>\u003Cp>Usage example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>AmcacheParser.exe -f C:\\Windows\\AppCompat\\Programs\\Amcache.hve --csv c:\\test\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>In some cases, export may fail with a prompt that the system is occupying the file Amcache.hve\u003C\u002Fp>\u003Cp>(2)\u003C\u002Fp>\u003Cp>Open source code (python)\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fwilliballenthin\u002Fpython-registry\u002Fblob\u002Fmaster\u002Fsamples\u002Famcache.py\u003C\u002Fp>\u003Cp>(3)\u003C\u002Fp>\u003Cp>Open source code (powershell)\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fyoda66\u002FGetAmCache\u002Fblob\u002Fmaster\u002FGet-Amcache.ps1\u003C\u002Fp>\u003Ch4>Method to clear records (RecentFileCache.bcf)\u003C\u002Fh4>\u003Cp>Modify file\u003C\u002Fp>\u003Cp>Detailed method will be introduced in the next article 'Penetration Techniques – Clearing Single Records in RecentFileCache.bcf and Amcache.hve'\u003C\u002Fp>\u003Ch4>Method to clear records (Amcache.hve)\u003C\u002Fh4>\u003Cp>Modify file\u003C\u002Fp>\u003Cp>The detailed method will be introduced in the next article 'Penetration Techniques – Clearing Single Records in RecentFileCache.bcf and Amcache.hve'\u003C\u002Fp>\u003Ch3>3. JumpLists\u003C\u002Fh3>\u003Cp>References:\u003C\u002Fp>\u003Cp>https:\u002F\u002Farticles.forensicfocus.com\u002F2012\u002F10\u002F30\u002Fforensic-analysis-of-windows-7-jump-lists\u002F\u003C\u002Fp>\u003Cp>Used to record recently used documents and applications by the user, typically displayed in the taskbar\u003C\u002Fp>\u003Cp>Location:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>%APPDATA%\\Microsoft\\Windows\\Recent\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Data is not encrypted\u003C\u002Fp>\u003Cp>Records update in real-time\u003C\u002Fp>\u003Ch4>Parsing tools\u003C\u002Fh4>\u003Cp>(1)\u003C\u002Fp>\u003Cp>Directly query the folder\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>dir %APPDATA%\\Microsoft\\Windows\\Recent\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>Methods to clear records\u003C\u002Fh4>\u003Cp>Clear files under the path\u003C\u002Fp>\u003Ch3>4. SRUM\u003C\u002Fh3>\u003Cp>Supported by Windows 8 and above systems\u003C\u002Fp>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.sans.org\u002Fcyber-security-summit\u002Farchives\u002Ffile\u002Fsummit-archive-1492184583.pdf\u003C\u002Fp>\u003Cp>Includes various information, including program execution time\u003C\u002Fp>\u003Cp>Data encryption\u003C\u002Fp>\u003Cp>Real-time update records\u003C\u002Fp>\u003Ch4>Parsing tools\u003C\u002Fh4>\u003Cp>(1)\u003C\u002Fp>\u003Cp>Command-line parsing\u003C\u002Fp>\u003Cp>Open-source code (Python)\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FMarkBaggett\u002Fsrum-dump\u003C\u002Fp>\u003Cp>Usage example:\u003C\u002Fp>\u003Cp>Requires template file SRUM_TEMPLATE.xlsx\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>srum_dump.exe --SRUM_INFILE c:\\Windows\\system32\\sru\\SRUDB.dat\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>During my testing, I found an issue with the command above; execution failed with the error: ESE File Not found: C:\\Windows\\System32\\sru\\SRUDB.dat\u003C\u002Fp>\u003Cp>It is necessary to copy SRUDB.dat to another directory before parsing\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>srum_dump.exe --SRUM_INFILE SRUDB.dat\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>Method to clear records\u003C\u002Fh4>\u003Cp>(To be introduced later)\u003C\u002Fp>\u003Ch2>0x05 Defense Recommendations\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Different systems support different methods, as shown in the figure below:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018724688_0_88bf0775ad.jpeg\">\u003C\u002Fp>\u003Cp>Image captured from https:\u002F\u002F1234n6-my.sharepoint.com\u002F:x:\u002Fp\u002Fadam\u002FEU3Fk3ec6NdPsSQx1eA1sfwB_R_fRa4tJ4c1FR6WJlWIEA?e=GRyu7r\u003C\u002Fp>\u003Cp>From a defense perspective, you can choose to regularly clean up file execution records in the system\u003C\u002Fp>\u003Cp>From a forensics perspective, attackers can modify and delete file execution records, so these records should not be blindly trusted\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article compiles the common locations of file execution records on Windows hosts (Windows 7 and above systems), verifies the content that Windows systems can record through practical testing, and analyzes methods for clearing some of these records.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>From a penetration perspective, after gaining access to a Windows host, it is necessary to fully understand the information of this Windows host, and file execution records are an important part.\u003C\u002Fp>\u003Cp>From a defense perspective, file execution records contain important system information, and it is necessary to specifically clear them.\u003C\u002Fp>\u003Cp>Therefore, this article will attempt to organize the common locations of file execution records on Windows hosts (Win7 and above systems), try to acquire and clear individual records, analyze exploitation ideas, and summarize defense methods.\u003C\u002Fp>\u003Cp>Reference links:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fblog.1234n6.com\u002F2018\u002F10\u002Favailable-artifacts-evidence-of.html?m=1\u003C\u002Fp>\u003Cp>https:\u002F\u002Fxz.aliyun.com\u002Ft\u002F3067#toc-5\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Obtaining file execution records from logs\u003C\u002Fli>\u003Cli>Obtaining file execution records from the registry\u003C\u002Fli>\u003Cli>Obtaining file execution records from files\u003C\u002Fli>\u003Cli>Instance Testing\u003C\u002Fli>\u003Cli>Exploitation and Defense Strategies\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Obtaining File Execution Records from Logs\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Process Creation (ID: 4688)\u003C\u002Fh3>\u003Cp>Usage Conditions:\u003C\u002Fp>\u003Cp>This feature is disabled by default in the system and requires manual configuration to enable\u003C\u002Fp>\u003Cp>Policy location: Computer Configuration -&gt; Policies -&gt; Windows Settings -&gt; Security Settings -&gt; Advanced Audit Configuration -&gt; Detailed Tracking\u003C\u002Fp>\u003Cp>Policy Name: Audit Process Creation\u003C\u002Fp>\u003Cp>Command line to retrieve log information:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wevtutil qe security \u002Frd:true \u002Ff:text \u002Fq:\"Event[System[(EventID=4688)]]\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>Methods to clear records:\u003C\u002Fh4>\u003Cp>For clearing individual log entries, refer to the previous article:\u003C\u002Fp>\u003Cp>\"Penetration Techniques – Deleting Single Windows Log Entries\"\u003C\u002Fp>\u003Ch3>2. Microsoft-Windows-Application-Experience Program-Inventory\u003C\u002Fh3>\u003Cp>References:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fjourneyintoir.blogspot.com\u002F2014\u002F03\u002Fexploring-program-inventory-event-log.html\u003C\u002Fp>\u003Cul>\u003Cli>800 (summary of software activities)\u003C\u002Fli>\u003Cli>903 &amp; 904 (new application installation)\u003C\u002Fli>\u003Cli>905 &amp; 906 (updated application)\u003C\u002Fli>\u003Cli>907 &amp; 908 (removed application).\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Command line to obtain log information:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wevtutil qe Microsoft-Windows-Application-Experience\u002FProgram-Inventory\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>3、Microsoft-Windows-Application-Experience Program-Telemetry\u003C\u002Fh3>\u003Cp>Command line to obtain log information:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wevtutil qe Microsoft-Windows-Application-Experience\u002FProgram-Telemetry\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x03 Obtain file execution records from the registry\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1、ShimCache\u003C\u002Fh3>\u003Cp>References:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.fireeye.com\u002Fblog\u002Fthreat-research\u002F2015\u002F06\u002Fcaching_out_the_val.html\u003C\u002Fp>\u003Cp>Used to record compatibility issues generated during the execution of Windows system programs\u003C\u002Fp>\u003Cp>Location:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Session Manager\\AppCompatCache\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>XP stores up to 96 records, Windows 7 and above store up to 1024 records\u003C\u002Fp>\u003Cp>Records the following content:\u003C\u002Fp>\u003Cul>\u003Cli>File path\u003C\u002Fli>\u003Cli>Last modified time\u003C\u002Fli>\u003Cli>Whether it was executed\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>ShimCache not only records the execution of exe files but also records files in the same directory as the exe file (if the file was not executed, the Executed attribute is no)\u003C\u002Fp>\u003Cp>Data is saved in a fixed format, storage structure can be referenced at:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.fireeye.com\u002Fcontent\u002Fdam\u002Ffireeye-www\u002Fservices\u002Ffreeware\u002Fshimcache-whitepaper.pdf\u003C\u002Fp>\u003Ch4>Parsing tools\u003C\u002Fh4>\u003Cp>(1)\u003C\u002Fp>\u003Cp>Open source code (C#)\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FEricZimmerman\u002FAppCompatCacheParser\u002F\u003C\u002Fp>\u003Cp>Usage example:\u003C\u002Fp>\u003Cp>Read the current system's registry and output the results to a specified path:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>AppCompatCacheParser.exe --csv c:\\test\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Output results sorted by last modified time:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>AppCompatCacheParser.exe --csv c:\\test -t\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Read a specified System file and output the results to a specified path:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>AppCompatCacheParser.exe --csv c:\\test -h C:\\Windows\\System32\\config\\SYSTEM\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(2)\u003C\u002Fp>\u003Cp>Open source code (Python)\u003C\u002Fp>\u003Cp>If you want to first export the registry file and then obtain parsing results in another system, you can use a Python-implemented script:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fmandiant\u002FShimCacheParser\u003C\u002Fp>\u003Cp>Usage example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg export \"HKLM\\SYSTEM\\CurrentControlSet\\Control\\Session Manager\\AppCompatCache\" ShimCache.reg\u003Cbr>ShimCacheParser.py -o out.csv -r c:\\test\\ShimCache.reg -t\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Export results via System file:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ShimCacheParser.py -o out.csv -i C:\\Windows\\System32\\config\\SYSTEM -t\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>Methods to clear records\u003C\u002Fh4>\u003Cp>ShimCache only updates after system reboot (logging off current user does not update it)\u003C\u002Fp>\u003Cp>That is to say, there are two methods to clear ShimCache records from the current system startup to shutdown:\u003C\u002Fp>\u003Cp>(1) Modify the registry\u003C\u002Fp>\u003Cp>Backup current registry:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg export \"HKLM\\SYSTEM\\CurrentControlSet\\Control\\Session Manager\\AppCompatCache\" ShimCache.reg\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>After system reboot, restore registry:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg import ShimCache.reg\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(2) Abnormal shutdown\u003C\u002Fp>\u003Cp>Skip the registry write operation, preventing recording of this system's startup-to-shutdown activity\u003C\u002Fp>\u003Cp>(3) Modify memory\u003C\u002Fp>\u003Cp>(Theoretically feasible)\u003C\u002Fp>\u003Ch3>2、UserAssist\u003C\u002Fh3>\u003Cp>Reference:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.4n6k.com\u002F2013\u002F05\u002Fuserassist-forensics-timelines.html\u003C\u002Fp>\u003Cp>Can be used to record the number of executions and the last execution time of Windows system programs\u003C\u002Fp>\u003Cp>Location:\u003C\u002Fp>\u003Cp>Current User:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>All Users:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>HKEY_USERS\\\u003Csid>\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\u003C\u002Fsid>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Subkey names are encrypted using ROT-13 (decryption is relatively simple)\u003C\u002Fp>\u003Cp>Records update in real-time\u003C\u002Fp>\u003Ch4>Parsing Tools\u003C\u002Fh4>\u003Cp>(1)\u003C\u002Fp>\u003Cp>Command-line parsing\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.nirsoft.net\u002Futils\u002Fuserassist_view.html\u003C\u002Fp>\u003Cp>Usage example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>UserAssistView.exe \u002Fstext out.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(2)\u003C\u002Fp>\u003Cp>Open source code (C#)\u003C\u002Fp>\u003Cp>https:\u002F\u002Fblog.didierstevens.com\u002Fprograms\u002Fuserassist\u002F\u003C\u002Fp>\u003Ch4>Method to clear records\u003C\u002Fh4>\u003Cp>Clear corresponding registry key values\u003C\u002Fp>\u003Ch3>3. MUICache\u003C\u002Fh3>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwhat-when-how.com\u002Fwindows-forensic-analysis\u002Fregistry-analysis-windows-forensic-analysis-part-8\u002F\u003C\u002Fp>\u003Cp>Used to record the file names of exe files, storing the absolute path of exe files and the corresponding exe file names in the registry\u003C\u002Fp>\u003Cp>Location:\u003C\u002Fp>\u003Cp>Current user:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\Software\\Microsoft\\Windows\\Shell\\MuiCache\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>All users:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>HKEY_USERS\\\u003Csid>\\Software\\Classes\\Local Settings\\Software\\Microsoft\\Windows\\Shell\\MuiCache\u003C\u002Fsid>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Data not encrypted\u003C\u002Fp>\u003Cp>Records updated in real-time\u003C\u002Fp>\u003Ch4>Parsing tool\u003C\u002Fh4>\u003Cp>(1)\u003C\u002Fp>\u003Cp>Command-line parsing\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.nirsoft.net\u002Futils\u002Fmuicache_view.html\u003C\u002Fp>\u003Cp>Usage example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>MUICacheView.exe \u002Fstext out.txt\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(2) Direct registry query\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg query \"HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\Software\\Microsoft\\Windows\\Shell\\MuiCache\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>Method to clear records\u003C\u002Fh4>\u003Cp>Clear corresponding registry key values\u003C\u002Fp>\u003Ch3>4、RunMRU\u003C\u002Fh3>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.forensicfocus.com\u002Fa-forensic-analysis-of-the-windows-registry\u003C\u002Fp>\u003Cp>Stores the history of programs launched via Win+U\u003C\u002Fp>\u003Cp>Location:\u003C\u002Fp>\u003Cp>Current User:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\RunMRU\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>All Users:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>HKEY_USERS\\\u003Csid>\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\RunMRU\u003C\u002Fsid>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Data is not encrypted\u003C\u002Fp>\u003Cp>Records update in real-time\u003C\u002Fp>\u003Ch4>Parsing tools\u003C\u002Fh4>\u003Cp>(1) Directly query the registry\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg query \"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\RunMRU\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>Methods to clear records\u003C\u002Fh4>\u003Cp>Delete the corresponding registry key values\u003C\u002Fp>\u003Ch3>5. AppCompatFlags Registry Keys\u003C\u002Fh3>\u003Cp>References:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fjourneyintoir.blogspot.com\u002F2013\u002F12\u002Frevealing-program-compatibility.html\u003C\u002Fp>\u003Cp>Save program execution records\u003C\u002Fp>\u003Cp>Location:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>HKLM\\Software\\Microsoft\\Windows NT\\CurrentVersion\\AppCompatFlags\\Layers\u003Cbr>HKCU\\Software\\Microsoft\\Windows NT\\CurrentVersion\\AppCompatFlags\\Layers\u003Cbr>HKCU\\Software\\Microsoft\\Windows NT\\CurrentVersion\\AppCompatFlags\\Compatibility Assistant\\Persisted\u003Cbr>HKCU\\Software\\Microsoft\\Windows NT\\CurrentVersion\\AppCompatFlags\\Compatibility Assistant\\Store\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>Parsing tools\u003C\u002Fh4>\u003Cp>(1) Direct registry query\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg query \"HKLM\\Software\\Microsoft\\Windows NT\\CurrentVersion\\AppCompatFlags\\Layers\"\u003Cbr>reg query \"HKCU\\Software\\Microsoft\\Windows NT\\CurrentVersion\\AppCompatFlags\\Layers\"\u003Cbr>reg query \"HKCU\\Software\\Microsoft\\Windows NT\\CurrentVersion\\AppCompatFlags\\Compatibility Assistant\\Persisted\"\u003Cbr>reg query \"HKCU\\Software\\Microsoft\\Windows NT\\CurrentVersion\\AppCompatFlags\\Compatibility Assistant\\Store\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>Methods to clear records\u003C\u002Fh4>\u003Cp>Clear the corresponding registry key values\u003C\u002Fp>\u003Ch2>0x04 Obtain file execution records from files\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1、Prefetch\u003C\u002Fh3>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.forensicmag.com\u002Farticle\u002F2010\u002F12\u002Fdecoding-prefetch-files-forensic-purposes-part-1\u003C\u002Fp>\u003Cp>Prefetch folder, used to store prefetch information for files that the system has accessed, which can speed up system startup\u003C\u002Fp>\u003Cp>Records the number of times a file has been run, last execution time, Hash, etc.\u003C\u002Fp>\u003Cp>Check if this feature is enabled:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg query \"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Session Manager\\Memory Management\\PrefetchParameters\" \u002Fv EnablePrefetcher\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cul>\u003Cli>0 = Disabled\u003C\u002Fli>\u003Cli>1 = Only Application launch prefetching enabled\u003C\u002Fli>\u003Cli>2 = Only Boot prefetching enabled\u003C\u002Fli>\u003Cli>3 = Both Application launch and Boot prefetching enabled\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Location:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>C:\\Windows\\Prefetch\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Data is saved in a fixed format with the extension .pf\u003C\u002Fp>\u003Ch4>Parsing tool\u003C\u002Fh4>\u003Cp>(1)\u003C\u002Fp>\u003Cp>Command-line parsing\u003C\u002Fp>\u003Cp>Open-source code (C#)\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FEricZimmerman\u002FPECmd\u003C\u002Fp>\u003Cp>Usage example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>PECmd.exe -d C:\\Windows\\Prefetch --csv c:\\temp\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Generates two files: \"time\"_PECmd_Output.csv and \"time\"_PECmd_Output_Timeline.csv\u003C\u002Fp>\u003Cp>\"time\"_PECmd_Output.csv stores detailed information\u003C\u002Fp>\u003Cp>\"time\"_PECmd_Output_Timeline.csv only stores a list of file names\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>PECmd.exe -d C:\\Windows\\Prefetch --json c:\\temp\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Generates multiple JSON files, each corresponding to one .pf file\u003C\u002Fp>\u003Ch4>Method to clear records\u003C\u002Fh4>\u003Cp>Delete the corresponding .pf file by filename\u003C\u002Fp>\u003Ch3>2. Amcache\u003C\u002Fh3>\u003Cp>References:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fjourneyintoir.blogspot.com\u002F2013\u002F12\u002Frevealing-recentfilecachebcf-file.html\u003C\u002Fp>\u003Cp>http:\u002F\u002Fwww.swiftforensics.com\u002F2013\u002F12\u002Famcachehve-in-windows-8-goldmine-for.html\u003C\u002Fp>\u003Cp>Used to track application compatibility issues with different executable files\u003C\u002Fp>\u003Cp>Data is saved in a fixed format\u003C\u002Fp>\u003Cp>Location:\u003C\u002Fp>\u003Cp>Windows 7:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>C:\\Windows\\AppCompat\\Programs\\RecentFileCache.bcf\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Only records file names\u003C\u002Fp>\u003Cp>Windows 8 and above:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>C:\\Windows\\AppCompat\\Programs\\Amcache.hve\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Records creation time, last modification time, SHA1, and some PE file header information\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>After installing KB2952664 on Win7 systems, Amcache.hve will also be supported, meaning both RecentFileCache.bcf and Amcache.hve contain file execution records\u003C\u002Fp>\u003Ch4>Parsing tool (RecentFileCache.bcf)\u003C\u002Fh4>\u003Cp>(1)\u003C\u002Fp>\u003Cp>Open source code (C#)\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fjwhwan9\u002FdumpBCF\u003C\u002Fp>\u003Cp>(2)\u003C\u002Fp>\u003Cp>Open source code (Python)\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fprolsen\u002Frecentfilecache-parser\u003C\u002Fp>\u003Cp>Usage example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>rfcparse.py -f C:\\Windows\\AppCompat\\Programs\\RecentFileCache.bcf\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>Parsing tool (Amcache.hve)\u003C\u002Fh4>\u003Cp>(1)\u003C\u002Fp>\u003Cp>Command-line parsing\u003C\u002Fp>\u003Cp>Open source code (C#)\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FEricZimmerman\u002FAmcacheParser\u003C\u002Fp>\u003Cp>Usage example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>AmcacheParser.exe -f C:\\Windows\\AppCompat\\Programs\\Amcache.hve --csv c:\\test\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>In some cases, export may fail with a prompt that the system is occupying the file Amcache.hve\u003C\u002Fp>\u003Cp>(2)\u003C\u002Fp>\u003Cp>Open source code (python)\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fwilliballenthin\u002Fpython-registry\u002Fblob\u002Fmaster\u002Fsamples\u002Famcache.py\u003C\u002Fp>\u003Cp>(3)\u003C\u002Fp>\u003Cp>Open source code (powershell)\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fyoda66\u002FGetAmCache\u002Fblob\u002Fmaster\u002FGet-Amcache.ps1\u003C\u002Fp>\u003Ch4>Method to clear records (RecentFileCache.bcf)\u003C\u002Fh4>\u003Cp>Modify file\u003C\u002Fp>\u003Cp>Detailed method will be introduced in the next article 'Penetration Techniques – Clearing Single Records in RecentFileCache.bcf and Amcache.hve'\u003C\u002Fp>\u003Ch4>Method to clear records (Amcache.hve)\u003C\u002Fh4>\u003Cp>Modify file\u003C\u002Fp>\u003Cp>The detailed method will be introduced in the next article 'Penetration Techniques – Clearing Single Records in RecentFileCache.bcf and Amcache.hve'\u003C\u002Fp>\u003Ch3>3. JumpLists\u003C\u002Fh3>\u003Cp>References:\u003C\u002Fp>\u003Cp>https:\u002F\u002Farticles.forensicfocus.com\u002F2012\u002F10\u002F30\u002Fforensic-analysis-of-windows-7-jump-lists\u002F\u003C\u002Fp>\u003Cp>Used to record recently used documents and applications by the user, typically displayed in the taskbar\u003C\u002Fp>\u003Cp>Location:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>%APPDATA%\\Microsoft\\Windows\\Recent\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Data is not encrypted\u003C\u002Fp>\u003Cp>Records update in real-time\u003C\u002Fp>\u003Ch4>Parsing tools\u003C\u002Fh4>\u003Cp>(1)\u003C\u002Fp>\u003Cp>Directly query the folder\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>dir %APPDATA%\\Microsoft\\Windows\\Recent\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>Methods to clear records\u003C\u002Fh4>\u003Cp>Clear files under the path\u003C\u002Fp>\u003Ch3>4. SRUM\u003C\u002Fh3>\u003Cp>Supported by Windows 8 and above systems\u003C\u002Fp>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.sans.org\u002Fcyber-security-summit\u002Farchives\u002Ffile\u002Fsummit-archive-1492184583.pdf\u003C\u002Fp>\u003Cp>Includes various information, including program execution time\u003C\u002Fp>\u003Cp>Data encryption\u003C\u002Fp>\u003Cp>Real-time update records\u003C\u002Fp>\u003Ch4>Parsing tools\u003C\u002Fh4>\u003Cp>(1)\u003C\u002Fp>\u003Cp>Command-line parsing\u003C\u002Fp>\u003Cp>Open-source code (Python)\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FMarkBaggett\u002Fsrum-dump\u003C\u002Fp>\u003Cp>Usage example:\u003C\u002Fp>\u003Cp>Requires template file SRUM_TEMPLATE.xlsx\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>srum_dump.exe --SRUM_INFILE c:\\Windows\\system32\\sru\\SRUDB.dat\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>During my testing, I found an issue with the command above; execution failed with the error: ESE File Not found: C:\\Windows\\System32\\sru\\SRUDB.dat\u003C\u002Fp>\u003Cp>It is necessary to copy SRUDB.dat to another directory before parsing\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>srum_dump.exe --SRUM_INFILE SRUDB.dat\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>Method to clear records\u003C\u002Fh4>\u003Cp>(To be introduced later)\u003C\u002Fp>\u003Ch2>0x05 Defense Recommendations\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Different systems support different methods, as shown in the figure below:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018724688_0_88bf0775ad-1.jpeg\">\u003C\u002Fp>\u003Cp>Image captured from https:\u002F\u002F1234n6-my.sharepoint.com\u002F:x:\u002Fp\u002Fadam\u002FEU3Fk3ec6NdPsSQx1eA1sfwB_R_fRa4tJ4c1FR6WJlWIEA?e=GRyu7r\u003C\u002Fp>\u003Cp>From a defense perspective, you can choose to regularly clean up file execution records in the system\u003C\u002Fp>\u003Cp>From a forensics perspective, attackers can modify and delete file execution records, so these records should not be blindly trusted\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article compiles the common locations of file execution records on Windows hosts (Windows 7 and above systems), verifies the content that Windows systems can record through practical testing, and analyzes methods for clearing some of these records.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",1373,"Onedaysec",6,"published","2026-02-02T08:06:59.416Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Windows File Execution Records: Penetration Acquisition & Clearing Techniques","Windows file execution records, penetration techniques, ShimCache, registry forensics, log analysis, security auditing, system artifacts, defense strategies",null,false,[],{"docs":43,"hasNextPage":40},[44,4,45,46,47],319,317,316,315,{"title":39,"description":39,"image":39},"2026-07-24T15:37:14.187Z","2026-07-23T16:01:22.260Z","draft","2026-07-23T16:05:19.052Z"]