One Day Sec

What is the purpose of RecentFileCache.bcf and Amcache.hve, and on which Windows versions are they used?

RecentFileCache.bcf tracks application execution history and is used on Windows 7 (and earlier?), while Amcache.hve replaces it on Windows 8 and later, recording additional metadata like creation time and SHA1. On Windows 7 with KB2952664 installed, both files coexist. For more on clearing these records, see the full article Penetration Techniques - Clearing Single Records in RecentFileCache.bcf and Amcache.hve.
RecentFileCache.bcfAmcache.hvefile execution recordsWindows forensicsexecution history

Browse all Q&A →