Ecosyste.ms: Awesome

An open API service indexing awesome lists of open source software.

Awesome Lists | Featured Topics | Projects

https://github.com/andrewrathbun/pcaparser

A PowerShell script that can be used to parse and convert to CSV the new Windows 11 artifacts found in C:\Windows\appcompat\pca
https://github.com/andrewrathbun/pcaparser

appcompat dfir powershell windows

Last synced: 27 days ago
JSON representation

A PowerShell script that can be used to parse and convert to CSV the new Windows 11 artifacts found in C:\Windows\appcompat\pca

Awesome Lists containing this project

README

        

# PCAParser

A PowerShell 5 script that can be used to parse and convert to CSV the new Windows 11 artifacts found in `C:\Windows\appcompat\pca`

## Documentation

Check out the blog post on AboutDFIR highlighting this new artifact [here](https://aboutdfir.com/new-windows-11-pro-22h2-evidence-of-execution-artifact/).

## Sample Data

Sample artifacts to test this script on can be found in the DFIRArtifactMuseum, specifically [here](https://github.com/AndrewRathbun/DFIRArtifactMuseum/tree/main/Windows%2FAmcache%2FWin11%2FRathbunVM).