amcache.drivers¶
$ target-query <path/to/target> -f amcache.drivers
Module |
|
Output |
|
Module documentation
Appcompat plugin for amcache.hve.
- Supported registry keys for old version of Amcache:
File
Programs
- Supported registry keys for new version of Amcache:
InventoryDriverBinary
InventoryDeviceContainer
InventoryApplication
InventoryApplicationFile
InventoryApplicationShortcut
- References:
Function documentation
Return InventoryDriverBinary records from Amcache hive.
Amcache is a registry hive that stores information about executed programs. The InventoryDriverBinary key holds the driver binaries that are in cache.