Skip to content

Services and Applications

Activity Cache
Extracts rows from the Activity SQLite table that records Windows 10 Timeline events
SQLite
Amcache Driver
Extracts driver metadata stored in the AmCache hive
Registry
Amcache Driver Xml
List drivers from various xml report files
XML
Amcache File
Retrieves cached executable file metadata from the Windows AmCache hive
Registry
Amcache Ie Addon Xml
List internet explorer addons from different xml report files
XML
Amcache Installer Xml
List installed software from various Xml files
XML
Amcache Program
Extracts metadata about installed programs from the Windows AmCache hive
Registry
Amcache Program Xml
Parse installed programs from AEINV WER xml reports
XML
Amcache Program Xml XML
Parse installed programs from FullCompatReport reports
XML
Amcache Program Xml XML
Parse installed programs from AEINV_PREVIOUS reports
XML
App Compat Cache
Extracts entries from the AppCompatCache value stored in the Windows System hive
Registry
Bam Dam
Extracts Activity Moderator (BAM/DAM) records from the Windows System hive
Registry
Listdlls
Parse output from Sysinternals ListDLL tool that lists loaded DLLs for running processes on Windows
ListDll
Mui Cache
Extracts entries from the per‑user MUI cache stored in the Registry hive
Registry
Prefetch
Parses Windows Prefetch files to extract execution metadata
Prefetch
Processes Orc
Extracts Windows processes data from an ORC‑generated CSV file
OrcProcesses1
Processes Orc Csv
Parses CSV files produced by ORC that enumerate running processes
Csv
Recent App
Extracts information about applications and files recently accessed by a user from the NtUser hive
Registry
Run Mru
Extracts entries from the RunMRU in the NTUser hive, which stores commands typed in the Windows + R dialog
Registry
Shim Db
Extracts information about the Windows Application Compatibility Shim database stored in the Software hive
Registry
Srum App Timeline
Srum table that tracks statistics about inputs (focus, keyboard, mouse, etc
Srum
Srum Application Resources
Srum table that tracks ressource usage for every exe that’s executed on the system whether it still exists on disk or not
Srum
Srum Energy Estimation
Parse data from srum
Srum
Srum Sdp Cpu
Srum table for windows server 2022 that tracks cpu time
Srum
Subject Interface Package
Extracts Subject Interface Package (SIP) records from the Windows Software hive
Registry
User Assist
Extracts execution data stored in the NTUser hive
Registry