creates a bodyfile from AmCache.hve
Project description
amcache2.py
creates a bodyfile from AmCache.hve
Installation
I recommend to use pipenv instead of venv, because using venv I had problems with https://github.com/construct/construct/pull/930
pipenv install amcache2
Usage
usage: amcache2.py [-h] registry_hive
Parse program execution entries from the Amcache.hve Registry hive
positional arguments:
registry_hive Path to the Amcache.hve hive to process
options:
-h, --help show this help message and exit
Example
pipenv run amcache2.py Amcache.hve | mactime -d -b -
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
amcache2-0.1.4.tar.gz
(14.9 kB
view hashes)
Built Distribution
amcache2-0.1.4-py3-none-any.whl
(14.9 kB
view hashes)