BAM and DAM
Also called Background Activity Moderator, Desktop Activity Moderator, bam registry key.
- PLATFORM
- Windows
- CATEGORY
- Program Execution
- INDEX
- 16 of 36
- PROVES
- 4 findings
- CANNOT PROVE
- 5 limits
- QUESTIONS
- 3 answered
A registry record, organised by user SID, of the last execution time of individual executables — the rare Windows artifact that attributes execution to an account directly.
Where it lives
SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\<SID> on Windows 10 version 1809 and later; earlier builds used ...\Services\bam\UserSettings\<SID>
Name the location in the preservation request rather than describing the artifact in general terms. A request that asks for the record by its path is one the responding party can act on and one a court can enforce; a request for “all forensic evidence of bam and dam” is neither.
What it records
The background activity moderator stores one value per executable under each user's SID, where the value name is the full NT device path of the binary and the data contains a timestamp for the last time it ran under that account. It exists to manage background activity rather than to keep records, so entries are cleared on a short cycle and the key is a rolling window rather than a history.
What it proves — and what it cannot
These two panels carry equal weight, deliberately. The right-hand column is not a disclaimer: it is the specific, mechanical reason an inference fails, and it is the column opposing counsel will read back to a witness on cross-examination.
What it proves
FINDINGS THIS ARTIFACT WILL SUPPORT ON ITS OWN TERMS.
- That a named executable ran under a specific user SID, which is direct account-level attribution for execution
- The last execution time of that binary under that account
- That a program ran which no longer exists on disk, since the value survives deletion of the file
- Execution of programs started outside the graphical shell, which UserAssist does not capture
What it cannot prove
INFERENCES IT WILL NOT CARRY, HOWEVER STRONGLY IT POINTS.
- Anything outside a short recent window. Entries are cleared on a rolling cycle commonly measured in days, so BAM speaks to the recent past and is silent about the period most disputes concern
- How many times a program ran, or when it ran before the recorded time. One timestamp per binary is stored and it is overwritten
- That the person associated with the account performed the launch, as against anyone using that session
- That the artifact exists at all on the system. The key path moved between Windows 10 releases and its presence and behaviour differ across builds, so it has to be located rather than assumed
- What the program did. There are no arguments, no targets and no outcome in the value
How the finding is attacked
An opinion built on this artifact meets these arguments. Each of them is answerable, and each of them is answered before the report is served rather than at a deposition.
- Establishing the rolling window and showing the events at issue predate anything the key could hold
- Pointing to the change in key location between Windows 10 releases and asking whether the tool read the right path for the build
- Arguing that a single overwritten timestamp cannot support any claim about a pattern of use
- Attacking the account-to-person link where the session was shared or left unlocked
What survives, and for how long
Values persist across reboots but are pruned on a rolling cycle, so BAM is a short-window artifact by design rather than by accident. Where a matter concerns activity from months earlier, it is usually already empty by the time the machine is imaged — which makes prompt preservation the difference between having it and not.
More matters are decided by what an artifact never kept than by what it says, which makes preservation timing the most consequential decision in the matter — and it is usually made months before anyone examines anything. The evidence preservation deadline calculator works from the date you first anticipated litigation.
Questions counsel ask
What does the BAM registry key show?
It shows the last time individual executables ran under a specific user account, stored one value per binary under that account's SID. That combination — execution plus direct account attribution — is unusual among Windows artifacts, which is why examiners reach for it. It records a single overwritten timestamp per program, so it supports no claim about how often anything ran.
How far back does BAM data go?
Not far. The background activity moderator exists to manage background processes rather than to keep records, and entries are cleared on a rolling cycle commonly measured in days. It is a snapshot of recent execution, not a history, so its value depends almost entirely on how quickly the machine was preserved after the events at issue.
Is BAM better evidence of execution than prefetch?
It is different rather than better, and the two answer different questions. Prefetch establishes that a binary ran on the machine, keeps up to eight run times on modern Windows, and carries no user attribution. BAM attributes a single last execution to a named account but holds only a short rolling window. A finding is strongest when both agree.
Terms used on this page
Every term below is defined in the forensic glossary — what it is, why a case turns on it, and what happens when it is mishandled.
Related artifacts
No artifact carries a matter on its own. These are the records that corroborate, contradict, or supply the timeline this one cannot.
Prefetch
Files Windows writes to speed up program launches, recording that an executable ran, when it last ran, how many times, and which files it loaded on startup.
UserAssist
A per-user registry record of programs and shortcuts launched through the Windows graphical shell, with a run count, focus time, and the last execution time.
SRUM (System Resource Usage Monitor)
A Windows database attributing network bytes sent and received, and application foreground time, to individual programs and user accounts in hourly buckets.
Windows Logon Events (4624 and 4625)
Security log records of each logon and failed logon attempt, naming the account, the logon type, the source workstation and address, and the resulting session identifier.
Whether the bam and damevidence in your matter supports the opinion built on it is a question with a testable answer. Law & Forensics retains court-tested digital forensic expert witnesses and forensic neutrals.
A conflicts check and scoping call follow, normally within one business day. Please do not send privileged or case-sensitive material until conflicts have cleared.
- Can This Artifact Prove That?
Start from the claim rather than the artifact: which records bear on it, and what no combination of them establishes.
- Computer forensics
The examination this artifact is collected and analysed in, scoped to a matter and reported so it can be tested.
- The artifact index
All 36 entries, grouped by what they bear on and filterable by platform.
- Daubert and digital evidence
Why an opinion stated one level too strongly is an admissibility problem rather than a point for cross-examination.
Attorney advertising / expert services. This page describes forensic artifacts and the procedural rules that govern expert evidence in general terms. Artifact behaviour varies by operating-system version, build, and configuration, and every observation has to be verified against the system actually in front of you. Nothing here is legal advice, and it is not a substitute for checking the rules, standing orders, and case law of your own forum.