Notifications
Clear all

Prefetch Question

1 Posts
1 Users
0 Reactions
33 Views
(@forensic_tester)
New Member
Joined: 3 hours ago
Posts: 1
Topic starter  

Hello All,

I have a question regarding Windows prefetch. Working on the rule of thumb that the creation timestamp is the first time the executable has been run, my CMD and powershell prefetch files have very recent creation timestamps, and I know I have used them numerous times in the past. There are not 1024 entries in the path, and I cannot understand this. There are also not numerous entries with an earlier date. Can anyone explain this?

Cheers

FT


 


   
Quote
Share: