reg-shim-cache

Loads information such as the path, volume, and last run time of all executable files, using the "AppCompatCache" data stored in the registry. You can check the name, path, volume information, and last run time of executable files with the loaded data and use it to analyze infringement accidents.

Syntax

reg-shim-cache [zippath=ZIPFILE_PATH] FILE_PATH
Required Parameters
FILE_PATH
Path to the registry file. If you provided the zippath option, input the file path in the ZIP file.
Optional Parameters
zippath=ZIPFILE_PATH
Path to the ZIP file.

Description

After running the reg-shellbags command, the output fields are as follows:

FieldTypeDescription
file_pathStringExecutable file path
modified_atDateLast modification time

Usage

  1. Retrieve by providing the file path.

    reg-shim-cache /opt/logpresso/testdata/registry/SYSTEM
    
  2. Retrieve when the zippath option is provided.

    reg-shim-cache zippath=/opt/logpresso/testdata/registry.zip registry/SYSTEM