Trees | Indices | Help |
|
---|
|
Shimcache plugin.
This code is based on work by:
# Authors: # Volatility Plugin Development # * Fred House - Mandiant, a FireEye Company # Twitter: @0xF2EDCA5A # # Windows Shimcache Analysis # * Andrew Davis - Mandiant, a FireEye Company # * Claudiu Teodorescu - FireEye Inc. # - Twitter: @cteo1
https://github.com/fireeye/Volatility-Plugins.git
and the paper: https://www.fireeye.com/blog/threat-research/2015/10/shim_shady_live_inv/shim-shady-part-2.html
Classes | |
ShimCacheMem Extract the Application Compatibility Shim Cache from kernel memory. |
Functions | |||
|
Variables | |
shimcache_xp_x86 =
|
|
shimcache_win7_x64 =
|
|
shimcache_win7_x86 =
|
|
shimcache_win8_x64 =
|
|
shimcache_win8_x86 =
|
|
shimcache_win10_x86 =
|
|
shimcache_win10_x64 =
|
|
__package__ =
|
Variables Details |
shimcache_xp_x86
|
shimcache_win7_x64
|
shimcache_win7_x86
|
shimcache_win8_x64
|
shimcache_win8_x86
|
shimcache_win10_x86
|
shimcache_win10_x64
|
Trees | Indices | Help |
|
---|
Generated by Epydoc 3.0.1 on Mon Oct 9 03:27:47 2017 | http://epydoc.sourceforge.net |