AmCache
Also called Amcache.hve, Amcache registry hive, InventoryApplicationFile.
- PLATFORM
- Windows
- CATEGORY
- Program Execution
- INDEX
- 13 of 36
- PROVES
- 5 findings
- CANNOT PROVE
- 5 limits
- QUESTIONS
- 3 answered
A registry hive maintained by the compatibility appraiser recording that binaries were present on the system, with their paths, publishers, sizes and a SHA-1 of the file.
Where it lives
C:\Windows\AppCompat\Programs\Amcache.hve
Name the location in the preservation request rather than describing the artifact in general terms. A request that asks for the record by its path is one the responding party can act on and one a court can enforce; a request for “all forensic evidence of amcache” is neither.
What it records
AmCache holds inventory keys describing files and installed applications the appraiser observed: full path, file size, linker and modification dates, publisher and version strings, and a SHA-1 hash of the file. It also inventories drivers and device containers, which makes it a secondary source of USB device history. Entries are written by a scheduled inventory task and at installation, so each key's last-write time reflects when the appraiser recorded the item rather than when a program ran. The key layout has changed across Windows 10 and 11 releases, so field names and locations should be confirmed against the build examined.
What it proves — and what it cannot
These two panels carry equal weight, deliberately. The right-hand column is not a disclaimer: it is the specific, mechanical reason an inference fails, and it is the column opposing counsel will read back to a witness on cross-examination.
What it proves
FINDINGS THIS ARTIFACT WILL SUPPORT ON ITS OWN TERMS.
- That a file with a given name, path, size and SHA-1 was present on the system when the appraiser inventoried it
- A file hash that can be compared against a known binary — the reason AmCache is valuable in tool-identification questions where no copy of the executable survives
- Publisher, version and linker date for a binary that has since been deleted
- Device and driver inventory entries corroborating removable-device history
- An approximate window in which the file was present, bounded by the inventory that recorded it
What it cannot prove
INFERENCES IT WILL NOT CARRY, HOWEVER STRONGLY IT POINTS.
- That the program ran. AmCache records presence and metadata; the appraiser inventories files it finds, whether or not they were ever executed, and treating an entry as proof of execution is a technical error rather than an overstatement
- When a program ran, for the same reason — the key's last-write time dates the inventory pass, not any execution
- Who put the file on the system or who used it. There is no user attribution in the hive
- That an absent entry means the file was never there. A file present and deleted between inventory passes may never be recorded at all
- That the recorded path is where the file was used. Inventory captures where the appraiser found it
How the finding is attacked
An opinion built on this artifact meets these arguments. Each of them is answerable, and each of them is answered before the report is served rather than at a deposition.
- Correcting any characterisation of an AmCache entry as evidence of execution, which is the most common error made with this artifact
- Showing that the key timestamp reflects a scheduled inventory pass rather than user activity, which can move a claimed event by hours or days
- Pointing to schema differences across Windows builds and asking whether the parsing tool was validated against the version examined
- Arguing that the appraiser's inventory scope may have missed the period at issue entirely
What survives, and for how long
The hive persists across reboots and retains entries for files deleted long ago, which is what makes it useful. Older entries are pruned as the hive is maintained, and its content is replaced wholesale on a rebuild or reinstall.
More matters are decided by what an artifact never kept than by what it says, which makes preservation timing the most consequential decision in the matter — and it is usually made months before anyone examines anything. The evidence preservation deadline calculator works from the date you first anticipated litigation.
Questions counsel ask
Does an AmCache entry prove a program was executed?
No, and this is the error most often made with the artifact. AmCache is an inventory maintained by the Windows compatibility appraiser: it records that a file was present, with its path, size, publisher and SHA-1 hash. The appraiser inventories files whether or not they were ever run. Prefetch, where it is enabled, is the artifact that supports an execution inference.
What is the AmCache timestamp actually recording?
The last-write time of an AmCache key reflects when the compatibility appraiser recorded the item, not when a program was installed or run. Because the appraiser runs on a schedule, an entry can be written hours or days after the file arrived. Using that timestamp as the time of an event is a mistake that can move a timeline materially.
Why is AmCache useful if it does not show execution?
Because it records a SHA-1 hash and full metadata for binaries that no longer exist on the system. Where a party deleted a portable archiver, a remote-access tool or a wiping utility, AmCache may hold enough to identify exactly which build it was and compare it against a known sample — a question no other artifact answers once the file itself is gone.
Terms used on this page
Every term below is defined in the forensic glossary — what it is, why a case turns on it, and what happens when it is mishandled.
Related artifacts
No artifact carries a matter on its own. These are the records that corroborate, contradict, or supply the timeline this one cannot.
ShimCache (AppCompatCache)
A capped registry cache of file paths the compatibility layer evaluated, holding each file's path and its last-modified time — and, on modern Windows, no reliable indicator of execution.
Prefetch
Files Windows writes to speed up program launches, recording that an executable ran, when it last ran, how many times, and which files it loaded on startup.
BAM and DAM
A registry record, organised by user SID, of the last execution time of individual executables — the rare Windows artifact that attributes execution to an account directly.
USBSTOR and USB Device History
The SYSTEM registry records which USB storage devices were attached to a machine, their vendor and product strings, and a small fixed set of first-seen and last-connected timestamps.
Whether the amcacheevidence in your matter supports the opinion built on it is a question with a testable answer. Law & Forensics retains court-tested digital forensic expert witnesses and forensic neutrals.
A conflicts check and scoping call follow, normally within one business day. Please do not send privileged or case-sensitive material until conflicts have cleared.
- Can This Artifact Prove That?
Start from the claim rather than the artifact: which records bear on it, and what no combination of them establishes.
- Computer forensics
The examination this artifact is collected and analysed in, scoped to a matter and reported so it can be tested.
- The artifact index
All 36 entries, grouped by what they bear on and filterable by platform.
- Daubert and digital evidence
Why an opinion stated one level too strongly is an admissibility problem rather than a point for cross-examination.
Attorney advertising / expert services. This page describes forensic artifacts and the procedural rules that govern expert evidence in general terms. Artifact behaviour varies by operating-system version, build, and configuration, and every observation has to be verified against the system actually in front of you. Nothing here is legal advice, and it is not a substitute for checking the rules, standing orders, and case law of your own forum.