Has anyone done any research about parsing prefetch files out of memory images? I was
working with the latest version of volatility 2.3 and found the mftparser plugin very
helpful. I was looking specifically at prefetch files and looking to possibly parse the
prefetch files if they exist in memory to see what files may have been accessed by
specific executables.
Just wondering if anyone has looked at this or thought about developing a plugin around
this?
Dave