Trust but Verify: Amcache’s OriginalFilename Field Isn’t Always Accurate
During an engagement at $lastdayjob we found a possible bug in AmCache so I wanted to dig into it a bit deeper. Mostly this is a call for help, and an explanation of how to test! TLDR Sometimes AmCache records an original filename is something when it either doesn’t exist in the original PE or […]