amcache.device_containers¶
$ target-query <path/to/target> -f amcache.device_containers
Module |
|
Output |
|
Module documentation
Appcompat plugin for amcache.hve.
- Supported registry keys for old version of Amcache:
File
Programs
- Supported registry keys for new version of Amcache:
InventoryDriverBinary
InventoryDeviceContainer
InventoryApplication
InventoryApplicationFile
InventoryApplicationShortcut
- References:
Function documentation
Return InventoryDeviceContainer records from Amcache hive.
Amcache is a registry hive that stores information about executed programs. The InventoryDeviceContainer key holds the device containers that are in cache. Example devices are bluetooth, printers, audio, etc.