Forensic journey: hunting evil within AmCache


When it comes to digital forensics, AmCache plays a vital role in identifying malicious activities in Windows systems. This artifact allows the identification of the execution of both benign and malicious software on a machine.

It is managed by the operating system, and at the time of writing this article, there is no known way to modify or remove AmCache data. Thus, in an incident response scenario, it could be the key to identifying lost artifacts (e.g., ransomware that auto-deletes itself), allowing analysts to search for patterns left by the attacker, such as file names and paths.

Read more…
Source: Kaspersky


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • Understanding and Mitigating Russian State-Sponsored Cyber Threats to U.S. Critical Infrastructure

    January 11, 2022

    This joint Cybersecurity Advisory (CSA)—authored by the Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), and National Security Agency (NSA)—is part of our continuing cybersecurity mission to warn organizations of cyber threats and help the cybersecurity community reduce the risk presented by these threats. This CSA provides an overview of Russian state-sponsored ...

  • What to Include in a Cybersecurity Disaster Recovery Plan

    January 11, 2022

    If the unthinkable were to happen to your business, what’s your disaster recovery plan? If bad actors were to inject ransomware into your system, what’s your process for a return to normal working? Google the words “What do I do if I have a cybersecurity breach” and the first twenty results will start with the ...

  • After ransomware attack, global logistics firm Hellmann warns of scam calls and mail

    December 20, 2021

    German logistics giant Hellmann has warned its customers and partners to be on the lookout for fraudulent calls and mail after the company was hit with a ransomware attack two weeks ago. In an update about the cyberattack that initially forced them to remove all connections to their central data center, the company said business operations ...

  • German logistics giant Hellmann reports cyberattack

    December 10, 2021

    Billion-dollar logistics firm Hellmann Worldwide Logistics reported a cyberattack this week that forced them to temporarily remove all connections to their central data center. The company said the shut down was having a “material impact” on their business operations. The German company operates in 173 countries, running logistics for a range of air and sea freights ...

  • Israel leads 10-country simulation of major cyberattack on world markets

    December 9, 2021

    Israel led a 10-country, 10-day-long simulation of a major cyberattack on the world’s financial system by “sophisticated” players, with the goal of minimizing the damage to banks and financial markets, the Finance Ministry said on Thursday. The Finance Ministry led the scenario with help from the Foreign Ministry, and said the “war game” was the first ...

  • Spar shops across northern UK shut after cyber attack hits payment processing abilities

    December 6, 2021

    The British arm of Dutch supermarket chain Spar has shut hundreds of shops after suffering an “online attack,” the company has confirmed to The Register. “This has not affected all SPAR stores across the North of England,” a Spar spokesman told us, “but a number have been impacted over the past 24 hours and we are ...