摘要
在Windows系统的Prefetch文件夹中存在大量的预读取文件,这些文件中实际上记录了具有一定取证价值的信息。文章试图通过运用一些分析工具来发现和提取文件中所包含的内容。
There are a lot of prefetch files in windows system. These files actually recorded many information of evidentiary value. The author tried to use some forensic tools to extract and analyze the information of the files.