Top Tweets for #ShimCache
Sizden gelen sorular;
Bir disk imajından #MFT, #Prefetch, #Amcache ve #Shimcache gibi artefaktları analiz etmek mümkün müdür? Örneğin, #CyberDefenders gibi platformlarda paylaşılan disk imajları bu tür analizler için yeterli veri sağlar mı? Bu tür analizler için hangi araçlar tercih edilmelidir?
In #DFIR, Windows operating systems leave behind a wealth of artifacts that can be invaluable, including #ShimCache (Application Compatibility Cache) and #AmCache (Application Activity Cache). In this blog, learn more about their significance: https://t.co/qCw9AY9bHM
🔍 It's #ForensicFriday! 🕵️♂️ Dive into our latest blog post, where we explore the importance of #Shimcache in digital forensics and incident response investigations. Discover how this Windows feature can reveal crucial insights for your #cybersecurity needs. 🔐👩💻
🔗 https://t.co/RYxUH8UAup
Windows Artifact Series || ShimCache
!!! Question : If we run #Executable from command prompt (#CMD) then, will it be visible in #ShimCache entries ? !!!
#dfir #digitalforensics #shimcache #4N6 #cybersecurity #WindowsArtifacts
https://t.co/bAW4Rk5Kve
1\ #APT Technique of #Persistence via #Shimcache Databases
As seen used by Fin7 and *Others*
In this example I used inject.dll to inject a bad.dll (the pop-up) and also called RedirectExe to open cmd.exe.
You can replace bad.dll with your Cobalt Strike beacon.
#APT Hunting: Look for #shimcache persistence (still being used by TAs) where "sdbinst.exe" is used to register a malicious shim db file to patch existing processes on disk i.e. svchost.exe. These files will be stored in the AppCompatFlags\Custom and InstalledSBD folders
Finally finished the next episode of DFIR in 120 seconds - Shimcache. Thanks for all your support. https://t.co/SDse6Y12FI or directly at youtube https://t.co/LtmeveuwN8 #DFIR #Shimcache

Learn how to leverage #Amcache and #Shimcache artifacts in a #digital #forensics case. https://t.co/tTGrhpJVqr #cybersecurity #infosec
Matias Bevilacqua from @Mandiant presenting on #Shimcache & #AmCache enterprise-wide "hunting" #ThreatHuntingSummit #DFIR

. @Mandiant consultants built a better way to do forensics on #ShimCache. Hope it wins @volatility plugin contest! https://t.co/sRX8TLUI0W
Most Popular Users

Elon Musk 
@elonmusk
240.4M followers

Barack Obama 
@barackobama
119.3M followers

Donald J. Trump 
@realdonaldtrump
111.7M followers

Cristiano Ronaldo 
@cristiano
110M followers

Narendra Modi 
@narendramodi
107M followers

Rihanna 
@rihanna
97.5M followers

NASA 
@nasa
92.1M followers

Justin Bieber 
@justinbieber
90.8M followers

KATY PERRY 
@katyperry
87.3M followers

Taylor Swift 
@taylorswift13
81.2M followers

Lady Gaga 
@ladygaga
72.7M followers

Kim Kardashian 
@kimkardashian
69.6M followers

Virat Kohli 
@imvkohli
69.4M followers

YouTube 
@youtube
68.6M followers

Bill Gates 
@billgates
63.7M followers

The Ellen Show
@theellenshow
62.5M followers

Neymar Jr 
@neymarjr
62.1M followers

CNN 
@cnn
61.9M followers

X 
@x
60.9M followers

Selena Gomez 
@selenagomez
60.4M followers










