Is there any way to reverse the hash at the end of a prefetch file to get the full path info? #DFIR
1
@DAVNADS The EXE name is included in the mapped files list in the PF file. Is that sufficient?
2
@hal_pomeranz lets pretend I don't have the file just the file name :-)
1
@DAVNADS AFAIK that PF file path hashing algorithm has not been reversed
Apr 4, 2013 · 10:32 PM UTC
1

