Difference between revisions of "Type Amcache"
Jump to navigation
Jump to search
| Line 33: | Line 33: | ||
=Truxton Exploiters= | =Truxton Exploiters= | ||
This file type is handled by the following ETLs: | This file type is handled by the following ETLs: | ||
| + | * [[Expand]] | ||
* [[Registry]] | * [[Registry]] | ||
* [[RegRipper]] | * [[RegRipper]] | ||
| + | |||
| + | =Items Produced= | ||
| + | Truxton will extract the following from this file type: | ||
| + | * <code>[[Type_File_Details]]</code> | ||
=Carve Meta Data= | =Carve Meta Data= | ||
Revision as of 05:34, 21 March 2024
| Defined Constant | Type_Amcache
|
| File Type Value | 884 |
| Parent Type | Registry |
| Carve | Yes |
| Format Details | No |
| Carve Meta Data | Yes |
| MIME Type | application/octet-stream
|
| Filename Extension | reg
|
AmCache
Description
Application Compatibility Registry
Truxton Exploiters
This file type is handled by the following ETLs:
Items Produced
Truxton will extract the following from this file type:
Carve Meta Data
When Truxton carves this file, it can populate the following columns in the [File] table:
LastWrite- When the file was last modifiedName- The name of the file