Difference between revisions of "Type Amcache"

From truxwiki.com
Jump to navigation Jump to search
Line 33: Line 33:
 
=Truxton Exploiters=
 
=Truxton Exploiters=
 
This file type is handled by the following ETLs:
 
This file type is handled by the following ETLs:
* [[Expand]]
+
* [[Registry]]
 
* [[RegRipper]]
 
* [[RegRipper]]
  

Revision as of 16:52, 18 March 2024

Details
Defined Constant Type_Amcache
File Type Value 884
Parent Type Registry
Carve Yes
Format Details No
Carve Meta Data Yes
MIME Type application/octet-stream
Filename Extension reg

AmCache

Description

Application Compatibility Registry

Truxton Exploiters

This file type is handled by the following ETLs:

Carve Meta Data

When Truxton carves this file, it can populate the following columns in the [File] table:

  • LastWrite - When the file was last modified
  • Name - The name of the file