Application execution artifact exercises
In this part, we will apply what we have learned so far. Try to work on the following questions:
- Using FTK Imager, export Prefetch from your local machine.
- Identify whether
CMD.exe
executed on your machine by usingAmcache.hve
. - Validate how many times
outlook.exe
was run on your machine by usingPECmd.exe
. - Investigate the loaded files referenced for
Calc.exe
on your machine.