Skip to content

Amcache source (execution / first-seen corroboration) #11

Description

@h4x0r

Parity item (feature-parity.md). USB Detective reads Amcache.hve InventoryDevicePnp entries for execution/first-seen corroboration.

Blocker: no fleet reader decodes Amcache (checked peripheral-core/-forensic, winreg-core/-forensic), and no real Amcache.hve USB corpus is on hand. Per ADR-0002 the parsing belongs in a fleet crate (an amcache-core on winreg-core), then usb-forensic wires it like the other registry sources.

To unblock: (1) build/adopt an Amcache reader crate; (2) source a real Amcache.hve with USB device entries + ground truth (regipy oracle).

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions