syscache
#
$ target-query <path/to/target> -f syscache
Module |
|
Output |
|
Module documentation
Plugin to parse Syscache.hve.
Reference: - https://dfir.ru/2018/12/02/the-cit-database-and-the-syscache-hive/
Function documentation
Parse the objects in the ObjectTable from the Syscache.hve file.