Skip to content
Security
Skill

/analyzing-windows-amcache-artifacts

Parses the Windows Amcache.hve registry hive with Eric Zimmerman''s

From plugin
cybersecurity-skills
28k200 skills
Install
$ npx -y skills add mukul975/Anthropic-Cybersecurity-Skills --skill analyzing-windows-amcache-artifacts --agent claude-code

How it fires

How this skill gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
  • You can call itInvoke it directly when you want it.
  • Slash command/analyzing-windows-amcache-artifacts

Context preview

The summary Claude sees to decide when to auto-load this skill.

Parses the Windows Amcache.hve registry hive with Eric Zimmerman''s

SKILL.md

analyzing-windows-amcache-artifacts.SKILL.md
name: analyzing-windows-amcache-artifacts
description: 'Parses the Windows Amcache.hve registry hive with Eric Zimmerman''s
  AmcacheParser and Timeline Explorer to extract evidence of program execution, application
  installation, and driver loading, including SHA-1 hash correlation with threat
  intel and timeline reconstruction. Use for Amcache forensics, program execution
  evidence gathering, or application compatibility cache investigations in DFIR work.

  '
domain: cybersecurity
subdomain: digital-forensics
tags:
- amcache
- windows-forensics
- program-execution
- AmcacheParser
- eric-zimmerman
- timeline-analysis
- DFIR
version: 1.0.0
author: mahipal
license: Apache-2.0
nist_csf:
- RS.AN-03
- DE.AE-02
- RS.MA-01
mitre_attack:
- T1070.004
- T1070.006
- T1036.005
- T1014
- T1005

Analyzing Windows Amcache Artifacts

When to Use

  • Determining which programs have existed or executed on a Windows system during incident response
  • Correlating SHA-1 hashes from Amcache against known malware databases (VirusTotal, CIRCL, MISP)
  • Building an application installation and execution timeline for forensic investigations
  • Identifying deleted executables that leave traces in Amcache even after file removal
  • Investigating insider threats by documenting which portable or unauthorized applications were present
  • Analyzing driver loading history to detect rootkits or malicious kernel modules

**Do not use** as sole proof of program execution. Amcache proves file existence and metadata registration, but ShimCache (AppCompatCache) and Prefetch provide stronger execution evidence. Use all three artifacts together for conclusive analysis.

Prerequisites

  • A forensic image or live triage copy of `C:\Windows\appcompat\Programs\Amcache.hve` (and associated `.LOG1`, `.LOG2` transaction logs)
  • Eric Zimmerman's AmcacheParser (`AmcacheParser.exe`) downloaded from https://ericzimmerman.github.io/
  • Eric Zimmerman's Timeline Explorer for viewing parsed CSV output
  • Optionally: Registry Explorer for manual hive inspection
  • A SHA-1 whitelist of known-good executables (e.g., NSRL hashset) for filtering
  • .NET 6+ runtime installed (required by current EZ tools)
  • Write access to an output directory for CSV results

Workflow

Step 1: Acquire the Amcache.hve File

Extract the Amcache hive from a forensic image or live system:

# From a live system (requires elevated privileges and raw copy tool)
# Amcache.hve is locked by the system; use a raw disk copy tool
# Option A: FTK Imager - mount image and navigate to:
# C:\Windows\appcompat\Programs\Amcache.hve
# Also collect: Amcache.hve.LOG1, Amcache.hve.LOG2

# Option B: Using KAPE for automated triage collection
kape.exe --tsource C: --tdest D:\Evidence\%m --target Amcache

# Option C: From a mounted forensic image (E: = mounted image)
copy "E:\Windows\appcompat\Programs\Amcache.hve" D:\Evidence\
copy "E:\Windows\appcompat\Programs\Amcache.hve.LOG1" D:\Evidence\
copy "E:\Windows\appcompat\Programs\Amcache.hve.LOG2" D:\Evidence\

Always collect the transaction log files (`.LOG1`, `.LOG2`) alongside the hive. AmcacheParser replays uncommitted transactions from these logs to recover the most complete data.

Step 2: Parse Amcache with AmcacheParser

Run AmcacheParser against the acquired hive:

# Basic parsing with CSV output
AmcacheParser.exe -f "D:\Evidence\Amcache.hve" --csv "D:\Evidence\Output"

# Parse with a SHA-1 whitelist to exclude known-good entries (NSRL)
AmcacheParser.exe -f "D:\Evidence\Amcache.hve" -w "D:\Whitelists\nsrl_sha1.txt" --csv "D:\Evidence\Output"

# Parse with a SHA-1 inclusion list (only show matches against known-bad hashes)
AmcacheParser.exe -f "D:\Evidence\Amcache.hve" -b "D:\IOCs\malware_sha1.txt" --csv "D:\Evidence\Output"

# Include deleted entries with high-precision timestamps
AmcacheParser.exe -f "D:\Evidence\Amcache.hve" --csv "D:\Evidence\Output" -i --mp

AmcacheParser produces multiple CSV files in the output directory:

| Output File | Contents | |-------------|----------| | `Amcache_AssociatedFileEntries.csv` | File entries with SHA-1 hashes, paths, sizes, and timestamps | | `Amcache_UnassociatedFileEntries.csv` | Orphaned file entries from older Amcache format | | `Amcache_ProgramEntries.csv` | Installed program metadata (name, publisher, version, install date) | | `Amcache_DeviceContainers.csv` | USB and device connection history | | `Amcache_DevicePnps.csv` | Plug-and-Play device driver information | | `Amcache_DriverBinaries.csv` | Loaded driver binaries with paths and hashes |

Step 3: Analyze File Entries for Suspicious Programs

Open the `AssociatedFileEntries.csv` in Timeline Explorer and examine key columns:

Key columns to review:
- ProgramId          : Links file to its parent program entry
- SHA1               : Hash for threat intel lookups
- FullPath           : Original file location on disk
- FileSize           : Size of the executable
- FileKeyLastWriteTimestamp : When the Amcache entry was last updated
- Name               : File name
- Publisher           : Code signing publisher (blank = unsigned)
- BinProductVersion  : Version string from the PE header
- LinkDate           : PE compilation timestamp (useful for detecting timestomping)

Filter for suspicious indicators:

# In Timeline Explorer, apply these filters:

# 1. Find unsigned executables (potentially malicious)
Publisher column = (empty)

# 2. Find executables from suspicious paths
FullPath contains: \temp\, \appdata\, \downloads\, \public\, \programdata\

# 3. Find executables with recent timestamps during incident window
FileKeyLastWriteTimestamp between: 2026-03-15 00:00:00 and 2026-03-16 00:00:00

# 4. Find executables with suspicious compilation dates (timestomping)
LinkDate year < 2015 AND FileKeyLastWriteTimestamp year = 2026

Step 4: Correlate SHA-1 Hashes with Threat Intelligence

Extract SHA-1 hashes and check against malware databases:

#
Read more
Ships withcybersecurity-skills

817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 29 security domains · Apache 2.0

Get the whole plugin

Other skills on cybersecurity-skills.