amcache.application_files

$ target-query <path/to/target> -f amcache.application_files
Details

Module

dissect.target.plugins.os.windows.amcache.AmcachePlugin

Output

records

Module documentation

Appcompat plugin for amcache.hve.

Supported registry keys for old version of Amcache:
  • File

  • Programs

Supported registry keys for new version of Amcache:
  • InventoryDriverBinary

  • InventoryDeviceContainer

  • InventoryApplication

  • InventoryApplicationFile

  • InventoryApplicationShortcut

References:

Function documentation

Return InventoryApplicationFile records from Amcache hive.

Amcache is a registry hive that stores information about executed programs. The InventoryApplicationFile key holds the application files that are in cache.

References: