Skip to content

Commit 8b8b0ca

Browse files
h4x0rclaude
andcommitted
docs: update validation report with dissect.esedb cross-validation
Rewrites the cross-implementation comparison section to use dissect.esedb 3.18 (Fox-IT, Apache-2.0) as an independent Python reference implementation instead of the internal two-path corroboration used in the original report. Key updates: - 24 table/file pairs now show zero-delta against dissect (up from 20 internal) - Rathbunvm win10 apps: 0 → 163 records (catalog last-wins bug fix) - Rathbunvm win11 apps: 0 → 791 records (same fix) - Adds "Bugs Found During Validation" section documenting ESE TAG swap, catalog first-wins deduplication, and u64 overflow — all discovered by testing against real Windows-generated files - Adds "Additional Data Sources Searched" (Arsenal Recon, null404, NIST CFReDS) - Updates date to 2026-05-15 Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
1 parent 6d5740c commit 8b8b0ca

1 file changed

Lines changed: 210 additions & 115 deletions

File tree

0 commit comments

Comments
 (0)