AmCache.hve
windowsExecution EvidenceDisk Image
Location
C:\Windows\appcompat\Programs\Amcache.hveDescription
Application compatibility cache hive tracking program execution with SHA1 hashes, file paths, publisher metadata, and first-execution timestamps.
Forensic Value
AmCache provides SHA1 hashes for executed binaries, enabling immediate VirusTotal lookups even after the attacker deletes the original file. First-execution timestamps establish when a tool was first introduced to the system. Entries persist across reboots and are harder to anti-forensic than Prefetch.
Tools Required
KAPEAmcacheParser (Eric Zimmerman)Registry Explorer (Eric Zimmerman)