Skip to content

App Compat Cache

Data Type: app_compat_cache
Python Parser: RegAppCompatCache

Description

Each row is an executable path cached by Windows Application Compatibility, with file modification time, cache flags, index, and registry provenance. Use it to establish that Windows knew of a path and correlate it with stronger execution artifacts. AppCompatCache presence alone is not definitive execution evidence, and formats and flag meaning vary by Windows version.

Timeline

Timeline Field Data Field
Related User key_security.owner_sid
Description path

Fields

Output Name Data Type Description
index Int sequential index of the cache entry
path String file path of the cached executable
modification_date DateTime last write time of the cached executable
flag1 String unknown 4‑byte flag data (Windows 8 AppCompatCache)
flag2 String unknown 4‑byte flag data (Windows 8 AppCompatCache)
key_path String full registry key name
key_modif_time DateTime last modification timestamp of the registry key
key_security Object
key_security.owner_sid String SID of the user that owns the registry key
key_security.group_sid String SID of the group that owns the registry key
key_security.control_flags[] Array[String] security descriptor control flags for the key
key_security.sacl_aces[] Array[Object]
key_security.sacl_aces[].ace_type String type of ACE (e.g., allow, deny)
key_security.sacl_aces[].ace_flags[] Array[String] ACE flags that modify inheritance or behavior
key_security.sacl_aces[].rights[] Array[String] permissions granted or denied by the ACE
key_security.sacl_aces[].account_sid String SID of the account the ACE applies to
key_security.sacl_aces[].ace_size Int declared ACE size in bytes
key_security.sacl_aces[].object_type_guid String GUID identifying the object type governed by the ACE
key_security.sacl_aces[].inherited_object_type_guid String GUID identifying the inherited object type governed by the ACE
key_security.sacl_aces[].raw_hex String raw ACE bytes preserved as hexadecimal
key_security.dacl_aces[] Array[Object]
key_security.dacl_aces[].ace_type String type of ACE (e.g., allow, deny)
key_security.dacl_aces[].ace_flags[] Array[String] ACE flags that modify inheritance or behavior
key_security.dacl_aces[].rights[] Array[String] permissions granted or denied by the ACE
key_security.dacl_aces[].account_sid String SID of the account the ACE applies to
key_security.dacl_aces[].ace_size Int declared ACE size in bytes
key_security.dacl_aces[].object_type_guid String GUID identifying the object type governed by the ACE
key_security.dacl_aces[].inherited_object_type_guid String GUID identifying the inherited object type governed by the ACE
key_security.dacl_aces[].raw_hex String raw ACE bytes preserved as hexadecimal