Skip to content

A PowerShell script that can be used to parse and convert to CSV the new Windows 11 artifacts found in C:\Windows\appcompat\pca

License

Notifications You must be signed in to change notification settings

AndrewRathbun/PCAParser

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

6 Commits
 
 
 
 
 
 
 
 

Repository files navigation

PCAParser

A PowerShell 5 script that can be used to parse and convert to CSV the new Windows 11 artifacts found in C:\Windows\appcompat\pca

Documentation

Check out the blog post on AboutDFIR highlighting this new artifact here.

Sample Data

Sample artifacts to test this script on can be found in the DFIRArtifactMuseum, specifically here.

About

A PowerShell script that can be used to parse and convert to CSV the new Windows 11 artifacts found in C:\Windows\appcompat\pca

Topics

Resources

License

Stars

Watchers

Forks

Packages

No packages published