Skip to content

PECmd

Eric Zimmerman's Prefetch Explorer command line tool for parsing Windows prefetch files.

When I Use It

  • Proving a program ran on a system, and when, even if the program has since been deleted
  • Finding attacker tools by name or by the files they loaded
  • Building an execution timeline across all prefetch files on a host

Installation

Common Tasks

Task Command
Parse one file PECmd.exe -f "C:\Windows\Prefetch\CALC.EXE-3FBEF7FD.pf"
Parse a directory PECmd.exe -d "C:\Windows\Prefetch"
Parse a directory to CSV PECmd.exe -d "C:\Windows\Prefetch" --csv C:\cases\output
Highlight a keyword PECmd.exe -k "plaguerat.ps1" -d "C:\cases\Prefetch"

Reading the Output

  • Run count and last run times: up to eight run times on Windows 8 and later
  • Files and directories referenced: what the program loaded in its first seconds, which often reveals its working folder and any payloads
  • Volume information: shows whether the program ran from a USB drive or network share

The CSV output includes a timeline file, which is the easiest view for building an execution timeline.

Resources