forked from EricZimmerman/KapeFiles
-
Notifications
You must be signed in to change notification settings - Fork 0
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
- Loading branch information
1 parent
2c7a13e
commit d0b3589
Showing
1 changed file
with
30 additions
and
0 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,30 @@ | ||
Description: PeaZip | ||
Author: Andrew Rathbun | ||
Version: 1.0 | ||
Id: 78c5d905-1992-4a9a-b582-a7f67baf9ec6 | ||
RecreateDirectories: true | ||
Targets: | ||
- | ||
Name: PeaZip Configuration Files | ||
Category: FileKnowledge | ||
Path: C:\Users\%user%\AppData\Roaming\PeaZip\ | ||
Recursive: True | ||
|
||
# Documentation | ||
# N/A | ||
# This directory contained the following files in my research VM: | ||
# C:\Users\*\AppData\Roaming\PeaZip\conf-lastgood.txt | ||
# C:\Users\*\AppData\Roaming\PeaZip\custedit.txt | ||
# C:\Users\*\AppData\Roaming\PeaZip\bookmarks.txt | ||
# C:\Users\*\AppData\Roaming\PeaZip\conf.txt | ||
# The two conf*.txt files contained a history of archives that were recently opened with PeaZip | ||
# Each file was identical to each other and had 650ish lines of data after about 10 minutes of testing with PeaZip. Except much more for a user who uses PeaZip as their primary archiving program | ||
# Bookmarks.txt appeared to contain entries for the default bookmarks that ship with PeaZip as well as user added bookmarks | ||
# Within this file, it stores the equivalent to a Shellbags-esque timestamp for the first time the user navigated to the bookmark and the last time | ||
# The most recently visited timestamp is overwritten each time the user visits that bookmark and a number above the timestamps is incremented for each visits | ||
For instance, my Bookmarks.txt had this entry: | ||
# 4 | ||
# 2021-03-28 15:37:36 | ||
# 2021-03-28 11:02:20 | ||
# 0 | ||
# C:\Users\%user$\Downloads |