Difference between revisions of "Type Amcache"
Jump to navigation
Jump to search
(Created page with "{| style="float:right;border:1px solid black" |+ Details | Defined Constant | <code>Type_Amcache</code> |- | File Type Value | 884 |- | Parent Type | Type_Windows_Registry|R...") |
|||
| (6 intermediate revisions by the same user not shown) | |||
| Line 1: | Line 1: | ||
{| style="float:right;border:1px solid black" | {| style="float:right;border:1px solid black" | ||
| − | |+ Details | + | |+ [[Type_Symbian_MIF|<<]] Details [[Type_SparkPeople|>>]] |
| Defined Constant | | Defined Constant | ||
| <code>Type_Amcache</code> | | <code>Type_Amcache</code> | ||
| Line 15: | Line 15: | ||
| Format Details | | Format Details | ||
| No | | No | ||
| + | |- | ||
| + | | Carve Meta Data | ||
| + | | Yes | ||
|- | |- | ||
| MIME Type | | MIME Type | ||
| Line 27: | Line 30: | ||
=Description= | =Description= | ||
Application Compatibility Registry | Application Compatibility Registry | ||
| + | |||
| + | =Truxton Exploiters= | ||
| + | This file type is handled by the following ETLs: | ||
| + | * [[Expand]] | ||
| + | * [[Registry]] | ||
| + | * [[RegRipper]] | ||
| + | |||
| + | =Items Produced= | ||
| + | Truxton will extract the following from this file type: | ||
| + | * <code>[[Type_File_Details]]</code> | ||
| + | |||
| + | =Carve Meta Data= | ||
| + | When Truxton carves this file, it can populate the following columns in the <code><nowiki>[</nowiki>[[File Table|File]]<nowiki>]</nowiki></code> table: | ||
| + | * <code>LastWrite</code> - When the file was last modified | ||
| + | * <code>Name</code> - The name of the file | ||
=Details= | =Details= | ||
| + | * [https://formats.kaitai.io/regf/ Kaitai] | ||
Latest revision as of 07:11, 6 March 2026
| Defined Constant | Type_Amcache
|
| File Type Value | 884 |
| Parent Type | Registry |
| Carve | Yes |
| Format Details | No |
| Carve Meta Data | Yes |
| MIME Type | application/octet-stream
|
| Filename Extension | reg
|
AmCache
Description
Application Compatibility Registry
Truxton Exploiters
This file type is handled by the following ETLs:
Items Produced
Truxton will extract the following from this file type:
Carve Meta Data
When Truxton carves this file, it can populate the following columns in the [File] table:
LastWrite- When the file was last modifiedName- The name of the file