Following on from the previous [DFIR TOOLS] posts. Hasher is a software application developed by Eric Zimmerman that is used to calculate and compare the hash values of files. A hash value is a unique code that is generated based on the contents of a file. By comparing the hash values of two files, it…
Tag: DFIR Tools
[DFIR TOOLS] AppCompatCacheParser, what is it & how to use!
Following on from the previous [DFIR TOOLS] posts. [DFIR TOOLS] Timeline Explorer, what is it & how to use! [DFIR TOOLS] AmcacheParser, what is it & how to use This time I will speak about AppCompatCacheParser again from the Eric Zimmerman suite. We will start with Erics description on its purpose:- AppCompatCache aka ShimCache parser. Handles…