Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merge ShimCacheParser into upstream #127

Open
exp0se opened this issue Aug 20, 2015 · 7 comments
Open

Merge ShimCacheParser into upstream #127

exp0se opened this issue Aug 20, 2015 · 7 comments

Comments

@exp0se
Copy link
Contributor

exp0se commented Aug 20, 2015

Hey,
i found this module ( https://github.com/davidhowell-tx/PS-ShimCacheParser ) for parsing AppCompatCache that have Kansa module. It works on windows 7, but unfortunately not on newer versions, but it shouldn't be hard to implement.
Can we consider merging it into upstream?

@EricZimmerman
Copy link

you can use my appcompat code if you can drop in the RegBinary bytes.

https://github.com/EricZimmerman/AppCompatCacheParser

@ghost
Copy link

ghost commented Jul 28, 2017

Pull request #163 was just added to get the output of ShimCacheParser.exe. It might be what you are looking for.

This route was chosen because Mandiant keeps the tool updated for newer OS versions. It should be easier to maintain that way.

@EricZimmerman
Copy link

except maniant doesnt keep it up to date =(

mandiant/ShimCacheParser#14

@ghost
Copy link

ghost commented Jul 28, 2017 via email

@EricZimmerman
Copy link

EricZimmerman commented Jul 29, 2017 via email

@ghost
Copy link

ghost commented Jul 29, 2017 via email

@ghost
Copy link

ghost commented Jul 31, 2017

Pull request #164 adds a new module Get-AppCompatCache that uses Eric's tool to get this data.

Thanks Eric!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants