Skip to content

fix: correct registry value parsing for Amcache plugin parameters#4965

Open
stetsbemueht wants to merge 1 commit intolog2timeline:mainfrom
stetsbemueht:main
Open

fix: correct registry value parsing for Amcache plugin parameters#4965
stetsbemueht wants to merge 1 commit intolog2timeline:mainfrom
stetsbemueht:main

Conversation

@stetsbemueht
Copy link
Copy Markdown

Updated the plugin to correctly read registry values for the following parameters of the windows:registry:amcache data type

  • sha1
  • file_size
  • language_code
  • file_version
  • company_name
  • product_name
  • program_identifier

Updated Test File.

This fix addresses issues caused by changes in the Amcache hive structure from Windows 7 to Windows 10.

Updated the plugin to correctly read registry values for the following parameters of the windows:registry:amcache data type
- sha1
- file_size
- language_code
- file_version
- company_name
- product_name
- program_identifier

Updated Test File.

This fix addresses issues caused by changes in the Amcache hive structure from Windows 7 to Windows 10.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant