Advanced Windows Forensic Engine (Amcache & Shimcache Correlation). Built with Sigma Rules, SHA-256 Integrity, and PII Masking (KVKK/GDPR). Educational Refactor of Amcache-EvilHunter.
-
Updated
Mar 27, 2026 - Python
Advanced Windows Forensic Engine (Amcache & Shimcache Correlation). Built with Sigma Rules, SHA-256 Integrity, and PII Masking (KVKK/GDPR). Educational Refactor of Amcache-EvilHunter.
C++ ShimCache (AppCompatCache) parser for execution artifact forensics
X-Ways Forensics Community Edition
Add a description, image, and links to the shimcache topic page so that developers can more easily learn about it.
To associate your repository with the shimcache topic, visit your repo's landing page and select "manage topics."