Services and Applications
Extracts rows from the Activity SQLite table that records Windows 10 Timeline events
SQLite
Extracts driver metadata stored in the
AmCache hiveRegistry
List drivers from various xml report files
XML
Retrieves cached executable file metadata from the Windows
AmCache hiveRegistry
List internet explorer addons from different xml report files
XML
List installed software from various Xml files
XML
Extracts metadata about installed programs from the Windows
AmCache hiveRegistry
Parse installed programs from AEINV WER xml reports
XML
Parse installed programs from
FullCompatReport reportsXML
Parse installed programs from
AEINV_PREVIOUS reportsXML
Extracts entries from the
AppCompatCache value stored in the Windows System hiveRegistry
Extracts Activity Moderator (BAM/DAM) records from the Windows
System hiveRegistry
Parse output from Sysinternals ListDLL tool that lists loaded DLLs for running processes on Windows
ListDll
Extracts entries from the per‑user MUI cache stored in the
Registry hiveRegistry
Parses Windows Prefetch files to extract execution metadata
Prefetch
Extracts Windows processes data from an ORC‑generated CSV file
OrcProcesses1
Parses CSV files produced by ORC that enumerate running processes
Csv
Extracts information about applications and files recently accessed by a user from the
NtUser hiveRegistry
Extracts entries from the
RunMRU in the NTUser hive, which stores commands typed in the Windows + R dialogRegistry
Extracts information about the Windows Application Compatibility Shim database stored in the
Software hiveRegistry
Srum table that tracks statistics about inputs (focus, keyboard, mouse, etc
Srum
Srum table that tracks ressource usage for every exe that’s executed on the system whether it still exists on disk or not
Srum
Parse data from srum
Srum
Srum table for windows server 2022 that tracks cpu time
Srum
Extracts Subject Interface Package (SIP) records from the Windows
Software hiveRegistry
Extracts execution data stored in the
NTUser hiveRegistry