How to Investigate with Windows Prefetch Files
https://www.tcm.rocks/certs-y - New forensics coursework (and possible cert) coming later this year! Until then, check out our existing blue team certifications, like the PSAA (Practical SOC Analyst Associate) and PSAP (Practical SOC Analyst Professional). What is Windows Prefetch? And why does Windows use it? Most importantly, how can we use it to our advantage as forensic examiners? It turns out, Windows Prefetch can provide some solid evidence of program execution. You can learn a surprising amount from it - even without using any forensic tools. Andrew Prince walks you through all of these things in a little over 15 minutes in today's video. What do you want to see Andrew explain next? Share your picks in the comments! ⬇️ #forensics #dfir #digitalforensics #cybersecurity #windows Sponsor a Video: https://www.tcm.rocks/Sponsors Pentests & Security Consulting: https://tcm-sec.com Get Trained: https://www.tcm.rocks/acad-y Get Certified: http://www.tcm.rocks/certs-y Merch: https://www.bonfire.com/store/tcm-sec... 0:00 - Introduction 00:44 - What is Windows Prefetch? 02:43 - Prefetch Configuration 05:40 - Prefetch Files 08:58 - Parsing Prefetch Files 11:49 - Hunting Anti-Forensics 13:14 - Scaling Prefetch Analysis 16:05 - Conclusion 📱Social Media📱 ___________________________________________ X: https://x.com/TCMSecurity Twitch: / thecybermentor Instagram: / tcmsecurity LinkedIn: / tcm-security-inc TikTok: / tcmsecurity Discord: / discord Facebook: / tcmsecure

Getting Started With The Windows Registry

A Guide to LNK File Forensics

Run These 9 CMD Commands Now to Repair Windows in Minutes

The Most Mysterious File On The Internet

NEVER install these programs on your PC... EVER!!!

How to Track the People Tracking YOU

Integrated SSDs Should Be Illegal, But Why Would They Care!

Trump Gets Booed & Falls Asleep During NBA Finals, Claims War is Almost Over & Goodbye Spencer Pratt

LIVE: Ransomware Memory Forensics | Cybersecurity | Blue Team

13 DOS commands you NEVER knew you NEEDED!

How Do I Store Files on My Computer and Not OneDrive?

Can I Delete Temporary Files in Windows?

THESE Apps Are SPYING on You — Shut Them Off NOW!

5 Cybersecurity Books That Made Me a Better Investigator

How to Remove All Viruses from Windows 10/11 (2025) | Tron Script

Passkeys Explained: Are They Actually Better Than Passwords?

LIVE: 🕵️ HTB Sherlocks! | Cybersecurity | Blue Team

How The FBI Finds Your DELETED Files

Linux File System/Structure Explained!

