Is there any way to reverse the hash at the end of a prefetch file to get the full path info? #DFIR
1
@DAVNADS The EXE name is included in the mapped files list in the PF file. Is that sufficient?
2
@hal_pomeranz lets pretend I don't have the file just the file name :-)
1
Replying to @DAVNADS
@DAVNADS AFAIK that PF file path hashing algorithm has not been reversed

Apr 4, 2013 · 10:32 PM UTC

1
This tweet is unavailable
@hunterforensics @hal_pomeranz thx saw this. Great research. Makes me want to go dark and figure out how to reverse it.
7