Forensic journey: hunting evil within AmCache


When it comes to digital forensics, AmCache plays a vital role in identifying malicious activities in Windows systems. This artifact allows the identification of the execution of both benign and malicious software on a machine.

It is managed by the operating system, and at the time of writing this article, there is no known way to modify or remove AmCache data. Thus, in an incident response scenario, it could be the key to identifying lost artifacts (e.g., ransomware that auto-deletes itself), allowing analysts to search for patterns left by the attacker, such as file names and paths.

Read more…
Source: Kaspersky


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • MGM files suit against FTC to block cyber attack investigation

    April 16, 2024

    MGM filed the suit yesterday (15 April) in Washington’s federal court against both the FTC and Lina M Khan as FTC chair. The suit refers to the large-scale cyber attack launched against MGM in September last year. MGM was forced to shut down certain systems across its US properties due to the attack. Access to MGM ...

  • Change Healthcare faces another ransomware threat – and it looks credible

    April 12, 2024

    For months, Change Healthcare has faced an immensely messy ransomware debacle that has left hundreds of pharmacies and medical practices across the United States unable to process claims. Now, thanks to an apparent dispute within the ransomware criminal ecosystem, it may have just become far messier still. In March, the ransomware group AlphV, which had claimed ...

  • IMF: Rising Cyber Threats Pose Serious Concerns for Financial Stability

    April 9, 2024

    Cyberattacks have more than doubled since the pandemic. While companies have historically suffered relatively modest direct losses from cyberattacks, some have experienced a much heavier toll. US credit reporting agency Equifax, for example, paid more than $1 billion in penalties after a major data breach in 2017 that affected about 150 million consumers. As we show ...

  • Improving Detection and Response: Making the Case for Deceptions

    April 5, 2024

    Let’s face it, most enterprises find it incredibly difficult to detect and remove attackers once they’ve taken over user credentials, exploited hosts or both. In the meantime, attackers are working on their next moves. That means data gets stolen and ransomware gets deployed all too often. And attackers have ample time to accomplish their goals. In ...

  • High Court order will deliver ‘swift management’ of compensation claims by those affected by PSNI data breach

    March 24, 2024

    Claims by officers and civilian staff following a major PSNI data breach will be managed in a “swift” manner following a High Court order being granted, it has been suggested. Following the granting of a Group Litigation Order (GLO), thousands of claims by those impacted by last year’s data breach can now be dealt with, the ...

  • UK: Criminal investigation into council cyber attack

    March 20, 2024

    Ccriminal investigation has started into a cyber attack that has disrupted Leicester City Council’s systems for more than a week. The council said it could not comment on the nature of the incident while the investigation was ongoing. It told the Local Democracy Reporting Service it still could not say if there had been a data ...