Is there any way to reverse the hash at the end of a prefetch file to get the full path info? #DFIR
1
Replying to @DAVNADS
@DAVNADS The EXE name is included in the mapped files list in the PF file. Is that sufficient?

Apr 4, 2013 · 10:26 PM UTC

2
Replying to @hal_pomeranz
@hal_pomeranz lets pretend I don't have the file just the file name :-)
1
@DAVNADS AFAIK that PF file path hashing algorithm has not been reversed
1
Replying to @hal_pomeranz
@hal_pomeranz its never that easy ;-)