C++ ShimCache (AppCompatCache) parser for execution artifact forensics
-
Updated
Feb 20, 2026 - C++
C++ ShimCache (AppCompatCache) parser for execution artifact forensics
X-Ways Forensics Community Edition
Read-only Windows forensic scanner for software traces — persistence, execution artifacts (Prefetch, Shimcache, BAM), user activity and Ghost Tasks correlation. 20+ modules mapped to MITRE ATT&CK.
Windows AppCompatCache (ShimCache) forensic analyzer — reads the AppCompatCache value from a SYSTEM hive and r
Add a description, image, and links to the shimcache topic page so that developers can more easily learn about it.
To associate your repository with the shimcache topic, visit your repo's landing page and select "manage topics."