In the world of Digital Forensics, finding a file on a hard drive is only half the battle. A suspect can easily argue, “I didn’t know that malware was there; I never clicked it.” To break this defense, a Forensic Operator must prove Execution.
Section 3.3 focuses on the “Evidence of Execution” artifacts. These are the footprints left behind by the Windows Operating System to improve performance, which inadvertently create a permanent record of every application ever launched, when it was launched, and where it lived on the disk.
1. Windows Prefetch (.pf): The “Fast Start” Receipt
The Prefetch mechanism was designed to speed up the Windows boot process and application launch times. When an application is executed, Windows monitors the files and metadata it loads during the first 10 seconds of its life. It then creates a .pf file in C:\Windows\Prefetch.
Forensic Intel in a Prefetch File:
- Executable Name: The name of the program that ran.
- Run Count: Exactly how many times the application has been executed.
- Last Execution Timestamp: The exact time (UTC) the program was last run. (Note: On Windows 8/10/11, the file stores the last eight execution timestamps).
- Files Loaded: A list of every DLL, configuration file, and data handle the program touched during startup.
- Volume Information: The serial number of the drive the program was launched from (proving if it ran from a suspicious USB).
The “Malware Catch”: If you find a prefetch file for mimikatz.exe but the file is no longer on the disk, the .pf file remains as proof that it was there and was executed.
2. Shimcache (AppCompatCache): The Compatibility Tracker
The Shimcache (officially the Application Compatibility Cache) is one of the most powerful artifacts in the Windows Registry. Its purpose is to identify backward compatibility issues for older programs.
The Forensic “Gotcha”:
Unlike Prefetch, which only tracks files that successfully ran, the Shimcache tracks every executable that was ever present on the system, even if it was just browsed in a folder or was blocked from running.
- Location: Resides in the
SYSTEMhive atHKLM\SYSTEM\CurrentControlSet\Control\Session Manager\AppCompatCache. - Volatility: Shimcache is stored in Memory (RAM) and only written to the Registry hive when the system is rebooted or shut down.
- Investigative Trap: If you pull the plug on a machine, you might lose the most recent Shimcache entries. This is why we capture RAM first in Section 2!
3. Amcache.hve: The “New” Execution DNA
While Shimcache tracks the possibility of execution, the Amcache.hve file is a hive that tracks the installation and execution of applications, including their SHA-1 hashes.
- Location:
C:\Windows\AppCompat\Programs\Amcache.hve. - Investigation Value: Because it records the SHA-1 hash of the executable, you can take that hash and search it on VirusTotal to see if it’s a known malware variant, even if the suspect renamed the file to
chrome.exe.
4. Superfetch / SysMain: The Modern Evolution
In modern Windows (10/11), Prefetch is often bundled into the SysMain service (formerly Superfetch). It creates .db files in the Prefetch directory. These files are more complex than traditional .pf files but provide a high-level timeline of user activity patterns, predicting when a user is likely to open certain programs.
| Artifact | Location | Best For Proving… |
| Prefetch (.pf) | C:\Windows\Prefetch | Exact time of launch and file dependencies. |
| Shimcache | SYSTEM Hive | Reconstructing a long-term timeline of executables. |
| Amcache | Amcache.hve | Getting the Hash (DNA) of the executed file. |
| UserAssist | NTUSER.DAT | Proving a specific user clicked the icon in the GUI. |
6. Technical Procedure: Parsing Execution Artifacts
We do not analyze these files manually with a text editor. We use the “Zimmerman Tools” to turn binary noise into actionable intelligence.
Step 1: Parse Prefetch
PECmd.exe -d "C:\Windows\Prefetch" --csv "C:\Analysis\PrefetchOutput"Step 2: Parse Shimcache
AppCompatCacheParser.exe -f "C:\Windows\System32\config\SYSTEM" --csv "C:\Analysis\ShimOutput"Step 3: Correlation Load both CSVs into Timeline Explorer. Filter for the suspect’s timeframe. If you see an entry in Shimcache for malware.exe followed immediately by a Prefetch entry for the same file, you have a “Lock” on the execution timeline.
7. The Anti-Forensic Challenge
Attackers often try to disable Prefetching to hide their tracks.
- The Tell: If the
C:\Windows\Prefetchfolder is empty or the Registry keyEnablePrefetcheris set to0, this is a massive red flag indicating an intentional attempt to hide activity. - The Counter: Even if they clear Prefetch, they almost always forget to clear the Shimcache or the Amcache, as those require complex registry manipulation or kernel-level access to wipe effectively while the OS is live.
Operator Intelligence Summary
- Focus Keyphrase: Windows Execution Artifacts Forensics
- Tags: Prefetch Analysis, Shimcache Forensics, Amcache.hve, Evidence of Execution, PECmd, Application Compatibility Cache
