Skip to main content

Python script to carve Windows Prefetch artifacts from arbitrary binary data

Description

The Windows application prefetch mechanism is in place to offer performance benefits when launching applications. It’s also one of the more beneficial forensic artifacts regarding evidence of applicaiton execution. prefetch-carve.py provides functionality for carving prefetch artifacts from binary data - such as unallocated disk space, raw memory images, etc. prefetch-carve.py will output to the specified file, and supports multiple output formats.

Supported Prefetch Types

Windows 10 Prefetch files are compressed, and are unable to be carved from disk in this manner. All other Prefetch formats are supported (Windows XP - Windows 8.1)

Command-Line Options

optional arguments:
  -h, --help            show this help message and exit
  -f FILE, --file FILE  Carve Prefetch files from the given file
  -o OUTFILE, --outfile OUTFILE
                        Write results to the given file
  -c, --csv             Output results in csv format
  -m, --mactime         Output results in mactime format
  -t, --tln             Output results in tln format
  -s SYSTEM, --system SYSTEM
                        System name (use with -t)

Testing

Thorough teseting is still underway. I plan to integrate this project with Travis CI shortly.

Installation

Using setup.py:

python setup.py install

Using pip:

pip install prefetchcarve

Metadata

Release files for prefetchcarve 1.1.2

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for prefetchcarve 1.1.2
File Size Uploaded
prefetchcarve-1.1.2.tar.gz 3.5 kB Details

Release files / prefetchcarve-1.1.2.tar.gz

Download URL prefetchcarve-1.1.2.tar.gz
Size 3.5 kB
Tags Source
SHA-256 checksum
How to use checksums
b358c59b30ffa234ef3fba3a1ad482cb2d89df12ab8d4f2fec2b1e20ccd82380
BLAKE2b-256 checksum
How to use checksums
b3294d0f72379f953393b3ce356f939c6b791d3b07cf073d7497bd6bb474f25d
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No

Release history Release notifications | RSS feed

This release

1.1.2 This release

1 release file

1.1.1

1 release file

1.1.0

1 release file

1.0.0

1 release file

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page