Skip to content

My DFIR Blog

Digital Forensics & Incident Response & Reverse Engineering & Vulnerability Research

  • Home
  • About Me
  • My Tools

Category: prefetch

Operation-based prefetching

April 9, 2024April 9, 2024 ~ Maxim Suhanov ~ 2 Comments

Have you ever seen files like “Op-EXPLORER.EXE-03C49D11-000000F5.pf“?

TL;DR: these are operation-based prefetch files. An application can ask the NT kernel to record I/O traces for specific operations, either on a per-application or per-thread basis. Then, these traces will be used to prefetch file access requests for that application.

Continue reading “Operation-based prefetching” →

Join 75 other subscribers
Create a website or blog at WordPress.com
  • Subscribe Subscribed
    • My DFIR Blog
    • Join 75 other subscribers
    • Already have a WordPress.com account? Log in now.
    • My DFIR Blog
    • Subscribe Subscribed
    • Sign up
    • Log in
    • Report this content
    • View site in Reader
    • Manage subscriptions
    • Collapse this bar