September 25, 2019
Mass Triage Part 5: Processing Returned Files – Amcache
Our story so far...
The list of IOCs is growing as the group conducts the triage. As they find new files related to the actor, the IR team goes back and searches the previous tools output to ensure everything has been picked up. With new files, mf.bat, ga86.exe, and rar.exe, from the ShimCache...