IT Forensics – Windows
Forensic analysis of ShimCache (AppCompatCache) – evidence of applications that have been run
The ShimCache, also known as the AppCompatCache, is an important Windows artefact. It contains information about executable files that have been recorded by the operating system and, depending on the version of Windows, can provide valuable insights into programme usage. However, the significance of this information depends on the operating system in question and the specific circumstances of each individual case.
In professional Windows forensics, the ShimCache is never analysed in isolation. Only by correlating it with artefacts such as Amcache, prefetch files, the Windows Registry, event logs, the Master File Table (MFT) and the USN Journal is it possible to carry out a reliable technical reconstruction.
Why LanCologne?
Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.
The examination is, as a matter of principle, carried out exclusively on a forensic copy or a forensic image. The original evidence remains unchanged and is stored in a manner that preserves its evidential integrity.
Our services
We analyse ShimCache entries, assess their significance within the respective Windows system and cross-check the results against other artefacts. All stages of the investigation are documented in a transparent manner and placed within the overall context of the investigation.
Typical areas of application
This is how a ShimCache forensic investigation is carried out
Once a forensic image has been created, the ShimCache is extracted from the relevant system data and analysed. This is followed by correlation with other digital evidence. Only then are the results technically assessed and fully documented.
Why is the ShimCache important?
The ShimCache can provide clues about programmes that have been detected by Windows. Whether it is possible to draw conclusions about whether a programme has actually been executed depends on the specific system and the overall analysis of all relevant artefacts.
Frequently Asked Questions
🔗 Related topics
LanCologne – Windows Forensics in Cologne
Do you need a professional analysis of the ShimCache or other Windows artefacts? LanCologne can assist you with the forensic-grade preservation of digital evidence and the objective analysis of complex Windows systems.
Related to this topic
- Forensic analysis of SRUM – Tracking system and network activity
- Forensic analysis of Windows Timeline – tracing user activities chronologically
- Forensic analysis of the Windows Reliability Monitor – tracking system changes and errors chronologically
- Forensic analysis of the Windows Notification Database – notifications as digital evidence