I had some problems with a Windows XP prefetch file, so I wrote a 010 Editor template using the Forensics Wiki’s information on prefetch files.
PFTemplate.zip (https)
MD5: 11F6BB8EC0D29CBCC7C2F269E9900AF0
SHA256: 4429380778C94E47427C1753BAF91E0D8AF78985AA9F3868CF3FC07456F7BAFA
Comes in handy, MSFT should stand up and publish more formats overall. Bit fed up having to reverse engineer things now and again slowing down progress.
Comment by Thierry Zoller — Saturday 4 August 2012 @ 13:20
@Thierry Yes, it is frustrating.
Comment by Didier Stevens — Sunday 5 August 2012 @ 7:31
[…] Prefetch File 010 Template 프리패치 파일에 대한 010Editor 템플릿이다. 포렌식을 공부하는 사람이라면 템플릿을 이용해 포맷을 자세히 살펴볼 수 있을 것이다. […]
Pingback by [Aug 2012] Newsletter | FORENSIC INSIGHT — Wednesday 17 October 2012 @ 14:06
[…] update to my Prefetch File 010 Template adds Sections A through […]
Pingback by Update: Prefetch File 010 Template | Didier Stevens — Monday 23 December 2013 @ 22:01