C++ ShimCache (AppCompatCache) parser for execution artifact forensics
-
Updated
Feb 20, 2026 - C++
C++ ShimCache (AppCompatCache) parser for execution artifact forensics
Read-only Windows forensic scanner for software traces — persistence, execution artifacts (Prefetch, Shimcache, BAM), user activity and Ghost Tasks correlation. 20+ modules mapped to MITRE ATT&CK.
X-Ways Forensics Community Edition
Windows AppCompatCache (ShimCache) forensic analyzer — reads the AppCompatCache value from a SYSTEM hive and r
To associate your repository with the shimcache topic, visit your repo's landing page and select "manage topics."