fs_amcache
Extracts executed binary full paths and SHA-1 hashes from Amcache.hve to identify program execution evidence.
Instructions
Program-execution evidence from Amcache.hve: executed binary full paths and their SHA-1 hashes. Find the Amcache.hve inode with fs_find first. Read-only via RegRipper.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| image | Yes | ||
| hive_inode | Yes | ||
| offset | No |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| result | Yes |