AmCache

Used to prove file existence and SHA1 hash

Deep dive into amcache:

https://www.ssi.gouv.fr/uploads/2019/01/anssi-coriin_2019-analysis_amcache.pdf

Operating System Availability

Major Version
Support
Major Version
Support

Windows 11

βœ…

Server 2019

βœ…

Windows 10

βœ…

Server 2016

βœ…

Windows 8

βœ…

Server 2012

βœ…

Windows 7

⚠️

Server 2008

⚠️

Windows Vista

❌

Server 2003

❌

Windows XP

❌

File Location:

  • C:\Windows\appcompat\Programs\Amcache.hve

Parsing Data

Considerations

  • Cannot be used to prove execution.

  • Automation may enter files into Amcache.

  • Used for file metadata and file presence evidence.

  • 31,457,280 Bytes

  • SHA1 Hashes first 30MB of file.

  • Remove first 4 zeros in hash to interpret legitimate hash.

Inventory Application:

Fully installed programs, not standalone/portable executables.

Inventory Application File:

Loose application files/standalone. Includes SHA1 hash.

  • FileID = SHA1 Hash

  • Link Data = Compiled date

Inventory Driver Binary:

Tracks installed drivers.

https://cyber.gouv.fr/sites/default/files/2019/01/anssi-coriin_2019-amcache_investigation.pdf

Anti Forensics

Last updated