amcache.application_files¶
$ target-query <path/to/target> -f amcache.application_files
Module |
|
Output |
|
Module documentation
Appcompat plugin for amcache.hve.
- Supported registry keys for old version of Amcache:
File
Programs
- Supported registry keys for new version of Amcache:
InventoryDriverBinary
InventoryDeviceContainer
InventoryApplication
InventoryApplicationFile
InventoryApplicationShortcut
- References:
Function documentation
Return InventoryApplicationFile records from Amcache hive.
Amcache is a registry hive that stores information about executed programs. The InventoryApplicationFile key holds the application files that are in cache.