amcache.device_containers

$ target-query <path/to/target> -f amcache.device_containers
Details

Module

dissect.target.plugins.os.windows.amcache.AmcachePlugin

Output

records

Module documentation

Appcompat plugin for amcache.hve.

Supported registry keys:

for old version of Amcache: * File * Programs

for new version of Amcache: • InventoryDriverBinary • InventoryDeviceContainer • InventoryApplication • InventoryApplicationFile * InventoryApplicationShortcut

References:

Function documentation

Return InventoryDeviceContainer records from Amcache hive.

Amcache is a registry hive that stores information about executed programs. The InventoryDeviceContainer key holds the device containers that are in cache. Example devices are bluetooth, printers, audio, etc.

References: