Windows Prefetch Forensics

December 20, 2016 | Views: 7991

Begin Learning Cyber Security for FREE Now!

FREE REGISTRATIONAlready a Member Login Here

Windows prefetch file system has an important place in cyber forensics. The prefetch system was implemented in order to improve the performance of the windows operating system. It prefetches the program into the system memory before the user actually uses it. In this way, it makes the whole process faster. The windows prefetch system helps us a lot in cyber forensics. It gives us information about the programs that have been run on the system, the last time the program was used, how many times it has been used and the path were the exe file is located. For example, let us assume that the suspect has used any prohibited software or program on the system. With the help of prefetch system, we can find out whether the suspect has actually used that particular program or software or not. Let us see its practical in the video below:

Share with Friends
Use Cybytes and
Tip the Author!
Share with Friends
Ready to share your knowledge and expertise?
  1. Great job,keep it up

  2. Thanks for the post Charanjeet. I came across this tutorial on you tube that got me started in this area, hopefully it might help you as well – (he uses WinPrefetchView)

Page 2 of 2«12
Comment on This

You must be logged in to post a comment.

Our Revolution

We believe Cyber Security training should be free, for everyone, FOREVER. Everyone, everywhere, deserves the OPPORTUNITY to learn, begin and grow a career in this fascinating field. Therefore, Cybrary is a free community where people, companies and training come together to give everyone the ability to collaborate in an open source way that is revolutionizing the cyber security educational experience.

Support Cybrary

Donate Here to Get This Month's Donor Badge


We recommend always using caution when following any link

Are you sure you want to continue?