
Sign up to save your podcasts
Or
In this episode, we’ll dive into two essential forensic artifacts in Windows: shellbags and the Program Compatibility Assistant (PCA). Shell bags provide valuable evidence of file and folder access, offering insights into user activity and file navigation. We’ll also explore PCA, which can reveal important information about file execution history. Together, these artifacts play a crucial role in uncovering key forensic details during investigations.
4.9
6161 ratings
In this episode, we’ll dive into two essential forensic artifacts in Windows: shellbags and the Program Compatibility Assistant (PCA). Shell bags provide valuable evidence of file and folder access, offering insights into user activity and file navigation. We’ll also explore PCA, which can reveal important information about file execution history. Together, these artifacts play a crucial role in uncovering key forensic details during investigations.
1,982 Listeners
364 Listeners
640 Listeners
370 Listeners
180 Listeners
1,017 Listeners
316 Listeners
408 Listeners
7,945 Listeners
189 Listeners
312 Listeners
76 Listeners
128 Listeners
43 Listeners
168 Listeners