AmCache-EvilHunter: Automating Evidence of Execution Extraction from the Amcache.hve Artifact

  • Cristian H. M. Souza Kaspersky / USP
  • Eduardo O. Chavarro Kaspersky
  • Daniel M. Batista USP

Resumo


Digital Forensics and Incident Response (DFIR) investigations frequently rely on native Windows artifacts to identify evidence of execution, reconstruct attacker activity, and generate indicators of compromise. Among these artifacts, Amcache.hve is especially valuable because it stores metadata about executables, installed applications, drivers, and shortcuts (such as file paths, timestamps, publisher information, and SHA-1 hashes). However, manually inspecting Amcache data can be time-consuming during incident response, especially when analysts need to filter large numbers of records and quickly verify suspicious hashes against threat intelligence sources. This paper presents AmCache-EvilHunter, an open-source command-line tool that parses Windows Amcache.hve registry hives, extracts relevant execution-related metadata, identifies suspicious executable names, filters records, and integrates Kaspersky OpenTIP and VirusTotal lookups. The tool was designed to reduce repetitive analysis tasks and support faster triage during real-world investigations.

Referências

Easttom, C., Butler, W., Phelan, J., Bhagavatula, R. S., Steuber, S., Rodriguez, K., Balkissoon, V. I., and Naseer, Z. (2024). Windows Forensics. Springer.

Gnanasekaran, V., Neudert, R., Heegaard, P. E., and Pernul, G. (2025). A role taxonomy in security-safety incident response. In International Conference on Availability, Reliability and Security, pages 286–304. Springer.

Jagathbala, R., Kumar, G. B., Geethanjali, D., and Nanthini, N. (2025). Forenxplorer: A smart digital forensic triage tool for fast and automated incident response. In 2025 10th International Conference on Smart Structures and Systems (ICSSS), pages 1–7. IEEE.

Joo, D., Lee, J., and Jeong, D. (2023). A reference database of windows artifacts for file-wiping tool execution analysis. Journal of forensic sciences, 68(3):856–870.

Lagny, B. (2019). Analysis of the amcache. ANSSI-DFIRSummit.

Neyaz, A. and Shashidhar, N. (2022). Windows prefetch forensics. In Breakthroughs in Digital Biometrics and Forensics, pages 191–210. Springer.

Souza, C. (2025). Forensic journey: hunting evil within amcache. Technical report, Kaspersky Securelist.

Souza, C. H., Pascoal, T., Neto, E. P., Sousa, G. B., SL Filho, F., Batista, D. M., and Silva, F. S. D. (2025). Sdn-based solutions for malware analysis and detection: State-of-the-art, open issues and research challenges. Journal of Information Security and Applications, 93:104145.

Tokarev, A. and Tokareva, V. (2023). Comparative analysis of amcache trace formation mechanisms in windows 10 and windows 11. In 2023 IEEE Ural-Siberian Conference on Biomedical Engineering, Radioelectronics and Information Technology (USBEREIT), pages 289–292. IEEE.
Publicado
01/09/2026
SOUZA, Cristian H. M.; CHAVARRO, Eduardo O.; BATISTA, Daniel M.. AmCache-EvilHunter: Automating Evidence of Execution Extraction from the Amcache.hve Artifact. In: SALÃO DE FERRAMENTAS - SIMPÓSIO BRASILEIRO DE CIBERSEGURANÇA (SBSEG), 26. , 2026, Armação dos Búzios/RJ. Anais [...]. Porto Alegre: Sociedade Brasileira de Computação, 2026 . p. 100-108. DOI: https://doi.org/10.5753/sbseg_estendido.2026.33555.

Artigos mais lidos do(s) mesmo(s) autor(es)

1 2 > >>