Forensic journey: hunting evil within AmCache


When it comes to digital forensics, AmCache plays a vital role in identifying malicious activities in Windows systems. This artifact allows the identification of the execution of both benign and malicious software on a machine.

It is managed by the operating system, and at the time of writing this article, there is no known way to modify or remove AmCache data. Thus, in an incident response scenario, it could be the key to identifying lost artifacts (e.g., ransomware that auto-deletes itself), allowing analysts to search for patterns left by the attacker, such as file names and paths.

Read more…
Source: Kaspersky


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • Ukraine’s secret cyber-defense that blunts Russian attacks: excellent backups

    June 8, 2022

    The Kremlin-backed cyberattack against satellite communications provider Viasat, which happened an hour before Russia invaded Ukraine, was “one of the biggest cyber events that we have seen, perhaps ever, and certainly in warfare,” according to Dmitri Alperovitch, a co-founder of CrowdStrike and chair of security-centric think tank Silverado Policy Accelerator. Alperovitch shared that opinion during a ...

  • Team of experts help Rutube to recover from the May 9 cyberattack

    May 11, 2022

    Rutube involved several expert teams, including a team of specialists from Positive Technologies security center, to deal with the aftermath of the May 9 cyberattack, the website said in its Telegram channel. “In order to investigate the attack and deal with its aftermath, several expert teams were involved, including a team of specialists from the Positive ...

  • SpringShell RCE vulnerability: Guidance for protecting against and detecting CVE-2022-22965

    April 4, 2022

    On March 31, 2022, vulnerabilities in the Spring Framework for Java were publicly disclosed. Microsoft is currently assessing the impact associated with these vulnerabilities. This blog is for customers looking for protection against exploitation and ways to detect vulnerable installations on their network of the critical remote code execution (RCE) vulnerability CVE-2022-22965 (also known as ...

  • IT outage at Scotland’s Heriot-Watt University enters second week

    March 24, 2022

    Edinburgh’s Heriot-Watt University has entered a second week of woe following a vist by an infosec nasty. The 200-year-old institution’s IT team first referred to the crisis as a “security incident” but a spokesperson confirmed to The Register that it was a cyber attack. A week on, things remain resolutely broken. VPN? Down. Oracle R12 Finance System? ...

  • ENISA: Incidents Handling and Cybercrime Investigations

    March 8, 2022

    The European Union Agency for Cybersecurity (ENISA) explores how CSIRTs, law enforcement agencies and the judiciary cooperate and how they can train together to better tackle cyber incidents and respond to cybercrime. The report published today facilitates the cooperation between CSIRTs and law enforcement agencies (LEAs) and looks into their interaction with the judiciary (judges and ...

  • Billion-dollar logistics giant Expeditors struggling to recover from cyberattack

    February 22, 2022

    Logistics and freight forwarding giant Expeditors International announced a cyberattack on Sunday that crippled some of their operating systems and continues to slow their operations around the globe. The Seattle-based freight company, which brought in $10.1 billion in revenue last year, said they shut down most of their operating systems globally after discovering the cyberattack. “The situation ...