Loading...
Loading...
Found 2 Skills
Parse Windows Prefetch (.pf) files with the windowsprefetch Python library to reconstruct application execution history, run counts, and accessed file/volume lists. Use when investigating renamed or masquerading binaries, verifying program execution timelines, or hunting for suspicious execution patterns in incident response.
Parse Windows Prefetch files to determine program execution history including run counts, timestamps, and referenced files for forensic investigation.