WxTcmd
How to use WxTCmd to parse the Windows Activities Cache in order to provide evidence of program execution during incident investigations.
Tool Name
Version
MITRE ATT&CK Tactic
MITRE ATT&CK Technique
Instructions
Extracting the ActivitiesCache.db file to a CSV
WxTcmd.exe -f 'C:\Path\To\ActivitiesCache.db' --csv 'C:\Path\To\Output'Output
Last updated
