Forensic journey: hunting evil within AmCache


When it comes to digital forensics, AmCache plays a vital role in identifying malicious activities in Windows systems. This artifact allows the identification of the execution of both benign and malicious software on a machine.

It is managed by the operating system, and at the time of writing this article, there is no known way to modify or remove AmCache data. Thus, in an incident response scenario, it could be the key to identifying lost artifacts (e.g., ransomware that auto-deletes itself), allowing analysts to search for patterns left by the attacker, such as file names and paths.

Read more…
Source: Kaspersky


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • EU lines up intel-sharing, cyber squads to stop hospital hacks

    January 15, 2025

    The European Union is ramping up support, an early-warning system and rapid response teams to help its hospitals fight off cyberattacks from hacker groups, it said Wednesday. The plan proposes setting up a European Cybersecurity Support Center for hospitals and the health care sector at the EU’s cybersecurity agency ENISA. That support center will provide tools ...

  • One Step Ahead in Cyber Hide-and-Seek: Automating Malicious Infrastructure Discovery With Graph Neural Networks

    January 13, 2025

    When launching and persisting attacks at scale, threat actors can inadvertently leave behind traces of information. They often reuse, rotate and share portions of their infrastructure when automating their campaign’s setup before launching an attack. Defenders can leverage this behavior by pivoting on a few known indicators to uncover newer infrastructure. This article describes the benefits ...

  • UK: Hackney Council still addressing 2020 cyber attack

    January 13, 2025

    Hackney Council has bought a new housing management system – technology that supports local authorities manage housing – as it tries to address the damage from a cyber attack four years ago. The October 2020 cyber attack left a lasting impact on services during a housing crisis which, according to the Local Democracy Report, has seen ...

  • Washington County implements cybersecurity policy to combat potential ransomware attacks

    December 27, 2024

    The Washington County commissioners approved a new “business continuity and disaster recovery policy and plan” designed to take a proactive approach in guarding against another cyber attack like the one that crippled the county government for nearly three weeks earlier this year. The policy, which was drafted with the help of outside cyber consultants and the ...

  • How the ransomware attack at Change Healthcare went down – a timeline

    December 18, 2024

    A ransomware attack earlier this year on UnitedHealth-owned health tech company Change Healthcare likely stands as one of the largest data breaches of U.S. health and medical data in history. Months after the February data breach, a “substantial proportion of people living in America” are receiving notice by mail that their personal and health information was ...

  • 63% of companies plan to pass data breach costs to customers

    December 4, 2024

    The rising practice of shaking down customers to pay for security shortfalls could have a silver lining for CISOs, as diluted price competitiveness could convince top brass of the ROI of cybersecurity investments. Consumers may be more on the hook for paying for the rising costs of data breaches than they realize, as companies increasingly turn ...