UserAssist — with a pinch of Salt — As an “Evidence of Execution”

Observation 1: Execution gets recorded under UserAssist even if an app/program is not executed

Figure 1. WinSCP.exe details — Before
Figure 2. Opening the path to the shortcut of WinSCP.exe through Cortona Search
Figure 3. Path to the shortcut of WinSCP.exe
Figure 4. WinSCP.exe details — After
Figure 5. Total Entries (295) under {CEBFF5CD-XX} — Before
Figure 6. Opening the path to the shortcut of mimikatz.exe through Cortona Search
Figure 7. Path to the shortcut of mimikatz.exe
Figure 7. mimikatz.exe gets registered even it was not executed

Observation 2: Multiple applications with 0 Run Count and blank “last execution” field

While reviewing UserAssist keys, I came across number of entries with 0 (Zero) Run Count.

Figure 8. summary of my UserAssist key
Figure 9. Snapshot of Programs with 0 Run Count and No dates

--

--

Get the Medium app

A button that says 'Download on the App Store', and if clicked it will lead you to the iOS App store
A button that says 'Get it on, Google Play', and if clicked it will lead you to the Google Play store