Commit 8b8b0ca
docs: update validation report with dissect.esedb cross-validation
Rewrites the cross-implementation comparison section to use dissect.esedb 3.18
(Fox-IT, Apache-2.0) as an independent Python reference implementation instead
of the internal two-path corroboration used in the original report.
Key updates:
- 24 table/file pairs now show zero-delta against dissect (up from 20 internal)
- Rathbunvm win10 apps: 0 → 163 records (catalog last-wins bug fix)
- Rathbunvm win11 apps: 0 → 791 records (same fix)
- Adds "Bugs Found During Validation" section documenting ESE TAG swap,
catalog first-wins deduplication, and u64 overflow — all discovered by
testing against real Windows-generated files
- Adds "Additional Data Sources Searched" (Arsenal Recon, null404, NIST CFReDS)
- Updates date to 2026-05-15
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>1 parent 6d5740c commit 8b8b0ca
1 file changed
Lines changed: 210 additions & 115 deletions
0 commit comments