SKIP TO CONTENT
PROGRAM EXECUTION16 / 36

BAM and DAM

Also called Background Activity Moderator, Desktop Activity Moderator, bam registry key.

PLATFORM
Windows
CATEGORY
Program Execution
INDEX
16 of 36
PROVES
4 findings
CANNOT PROVE
5 limits
QUESTIONS
3 answered
WHAT IT IS

A registry record, organised by user SID, of the last execution time of individual executables — the rare Windows artifact that attributes execution to an account directly.

Where it lives

SYSTEM\CurrentControlSet\Services\bam\State\UserSettings\<SID> on Windows 10 version 1809 and later; earlier builds used ...\Services\bam\UserSettings\<SID>

Name the location in the preservation request rather than describing the artifact in general terms. A request that asks for the record by its path is one the responding party can act on and one a court can enforce; a request for “all forensic evidence of bam and dam” is neither.

What it records

The background activity moderator stores one value per executable under each user's SID, where the value name is the full NT device path of the binary and the data contains a timestamp for the last time it ran under that account. It exists to manage background activity rather than to keep records, so entries are cleared on a short cycle and the key is a rolling window rather than a history.

What it proves — and what it cannot

These two panels carry equal weight, deliberately. The right-hand column is not a disclaimer: it is the specific, mechanical reason an inference fails, and it is the column opposing counsel will read back to a witness on cross-examination.

What it proves

FINDINGS THIS ARTIFACT WILL SUPPORT ON ITS OWN TERMS.

  • That a named executable ran under a specific user SID, which is direct account-level attribution for execution
  • The last execution time of that binary under that account
  • That a program ran which no longer exists on disk, since the value survives deletion of the file
  • Execution of programs started outside the graphical shell, which UserAssist does not capture

What it cannot prove

INFERENCES IT WILL NOT CARRY, HOWEVER STRONGLY IT POINTS.

  • Anything outside a short recent window. Entries are cleared on a rolling cycle commonly measured in days, so BAM speaks to the recent past and is silent about the period most disputes concern
  • How many times a program ran, or when it ran before the recorded time. One timestamp per binary is stored and it is overwritten
  • That the person associated with the account performed the launch, as against anyone using that session
  • That the artifact exists at all on the system. The key path moved between Windows 10 releases and its presence and behaviour differ across builds, so it has to be located rather than assumed
  • What the program did. There are no arguments, no targets and no outcome in the value

How the finding is attacked

An opinion built on this artifact meets these arguments. Each of them is answerable, and each of them is answered before the report is served rather than at a deposition.

  • Establishing the rolling window and showing the events at issue predate anything the key could hold
  • Pointing to the change in key location between Windows 10 releases and asking whether the tool read the right path for the build
  • Arguing that a single overwritten timestamp cannot support any claim about a pattern of use
  • Attacking the account-to-person link where the session was shared or left unlocked

What survives, and for how long

Values persist across reboots but are pruned on a rolling cycle, so BAM is a short-window artifact by design rather than by accident. Where a matter concerns activity from months earlier, it is usually already empty by the time the machine is imaged — which makes prompt preservation the difference between having it and not.

More matters are decided by what an artifact never kept than by what it says, which makes preservation timing the most consequential decision in the matter — and it is usually made months before anyone examines anything. The evidence preservation deadline calculator works from the date you first anticipated litigation.

Questions counsel ask

What does the BAM registry key show?

It shows the last time individual executables ran under a specific user account, stored one value per binary under that account's SID. That combination — execution plus direct account attribution — is unusual among Windows artifacts, which is why examiners reach for it. It records a single overwritten timestamp per program, so it supports no claim about how often anything ran.

How far back does BAM data go?

Not far. The background activity moderator exists to manage background processes rather than to keep records, and entries are cleared on a rolling cycle commonly measured in days. It is a snapshot of recent execution, not a history, so its value depends almost entirely on how quickly the machine was preserved after the events at issue.

Is BAM better evidence of execution than prefetch?

It is different rather than better, and the two answer different questions. Prefetch establishes that a binary ran on the machine, keeps up to eight run times on modern Windows, and carries no user attribution. BAM attributes a single last execution to a named account but holds only a short rolling window. A finding is strongest when both agree.

Terms used on this page

Every term below is defined in the forensic glossary — what it is, why a case turns on it, and what happens when it is mishandled.

No artifact carries a matter on its own. These are the records that corroborate, contradict, or supply the timeline this one cannot.

A FINDING ON THIS ARTIFACT

Whether the bam and damevidence in your matter supports the opinion built on it is a question with a testable answer. Law & Forensics retains court-tested digital forensic expert witnesses and forensic neutrals.

A conflicts check and scoping call follow, normally within one business day. Please do not send privileged or case-sensitive material until conflicts have cleared.

WEEKLY BRIEFING

Digital evidence, explained for litigators.

One email a week on forensic method, digital evidence, and expert testimony — written for counsel, not for technicians. No pitches.

DOUBLE OPT-IN · UNSUBSCRIBE ANY TIME · PRIVACY POLICY

  • Can This Artifact Prove That?

    Start from the claim rather than the artifact: which records bear on it, and what no combination of them establishes.

  • Computer forensics

    The examination this artifact is collected and analysed in, scoped to a matter and reported so it can be tested.

  • The artifact index

    All 36 entries, grouped by what they bear on and filterable by platform.

  • Daubert and digital evidence

    Why an opinion stated one level too strongly is an admissibility problem rather than a point for cross-examination.

← BACK TO THE ARTIFACT INDEX

Attorney advertising / expert services. This page describes forensic artifacts and the procedural rules that govern expert evidence in general terms. Artifact behaviour varies by operating-system version, build, and configuration, and every observation has to be verified against the system actually in front of you. Nothing here is legal advice, and it is not a substitute for checking the rules, standing orders, and case law of your own forum.