amcache.applications

$ target-query <path/to/target> -f amcache.applications
Details

Module

dissect.target.plugins.os.windows.amcache.AmcachePlugin

Output

records

Module documentation

Appcompat plugin for amcache.hve.

Supported registry keys for old version of Amcache:
  • File

  • Programs

Supported registry keys for new version of Amcache:
  • InventoryDriverBinary

  • InventoryDeviceContainer

  • InventoryApplication

  • InventoryApplicationFile

  • InventoryApplicationShortcut

References:

Function documentation

Return InventoryApplication records from Amcache hive.

Amcache is a registry hive that stores information about executed programs. The InventoryApplication key holds all application objects that are in cache.

References: