Name
Windows Store & Apps (APPX) Analysis
Speakers
Yogesh Khatri | Assistant Professor & Program Director | Champlain College
Jack Farley | Student | Champlain College
Description
As more desktop apps transition to the Windows app store (aka Windows Store) there is a need to understand these apps which are written in UWP (Universal Windows Platform). These apps are distributed as APPX containers and follow a common theme regarding artifact locations. As of now, most forensic tools either do not report them at all or just provide a basic listing of installed apps. In this talk, we will outline the artifacts related to identifying installed apps, understanding various IDs(AppID, product_id, AUMID), versions, install/uninstall locations, timestamps, execution/usage artifacts and cache locations in registry and on disk for examination. We also analyze some popular apps and sideloading (installing an app outside the store).