fs_shimcache
Extract paths and timestamps of executed binaries from the SYSTEM hive's Shimcache using RegRipper for read-only forensic evidence collection.
Instructions
Program-execution evidence from the SYSTEM hive's Application Compatibility Cache (Shimcache): paths and timestamps of binaries that ran or were present. Find the SYSTEM hive inode with fs_find first. Read-only via RegRipper.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| image | Yes | ||
| hive_inode | Yes | ||
| offset | No |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| result | Yes |