Prefetch

Prefetch

Prefetch (Windows)

Prefetch is a Windows mechanism that speeds up the launching of programs by creating a small file with startup information for each executed application. Forensically this is a stroke of luck: prefetch files prove which programs ran, when and how often. They are a central indicator of program execution.

History & facts. Actually only a performance feature, prefetch leaves a valuable artefact: for each executed program a file is created that contains, among other things, the name, timestamps of the last executions and an execution counter. For forensics this is a direct answer to the question of whether and when a particular program — such as a malicious tool — ran on the system, even if the executable itself was long since removed.

Outlook & recommendation. Prefetch is one of the most reliable indicators of program execution under Windows and thus an important building block of timeline analysis. Since attackers know this artefact, its absence or targeted deletion can itself be a clue (anti-forensics). For robust conclusions, prefetch traces are merged with other execution evidence and timestamps (Master File Table (MFT), registry, logs) — agreements corroborate, contradictions expose.

Prefetch — Prefetch