Windows 7 · AppCompat · 100% local
RecentFileCache.bcf parser, in your browser.
Drop a Windows 7 RecentFileCache.bcf file and inspect its cached file paths. Parsing runs locally in WebAssembly — your evidence never leaves your machine.
- No upload — WebAssembly in your browser
- Drop a .bcf, a folder or a KAPE / Velociraptor ZIP
- Saved sessions stay in this browser
- CSV and JSON export
RecentFileCache parser
Drop a RecentFileCache.bcf, a triage folder or a KAPE / Velociraptor ZIP here, or click to choose.
Parsing runs 100% client-side via WebAssembly. The file is never uploaded.
Synthetic Windows 7 RecentFileCache.bcf from a fictional intrusion — no real data. This artifact only exists on Windows 7 / Server 2008 R2 (Amcache.hve replaced it on Windows 8+).
How to get your data
From a Windows 7 host to results in about two minutes. Take the first method that fits: every command is ready to paste.
- 1CollectRun one command on the host
- 2DropDrop the file, the C:\triage folder or the ZIP here
- 3Stays localParsed in your browser, never uploaded
Needs: Windows 7 or Server 2008 R2, PowerShell (the default 64-bit one) started with Run as administrator.
Current file, through a temporary shadow copy
The live file is held open, so this snapshots C:, copies RecentFileCache.bcf out of the snapshot into C:\triage, then deletes the snapshot.
New-Item -ItemType Directory -Force C:\triage | Out-Null
$s = ([wmiclass]'Win32_ShadowCopy').Create('C:\', 'ClientAccessible')
$sc = Get-WmiObject Win32_ShadowCopy -Filter "ID='$($s.ShadowID)'"
cmd /c copy /b /y "$($sc.DeviceObject)\Windows\AppCompat\Programs\RecentFileCache.bcf" C:\triage\RecentFileCache.bcf
$sc.Delete()Also: older versions from existing shadow copies
Each snapshot holds its own copy, often with entries already purged from the live file. Saved as RecentFileCache_HarddiskVolumeShadowCopyN.bcf; snapshots of other drives just print "cannot find the path".
New-Item -ItemType Directory -Force C:\triage | Out-Null
Get-WmiObject Win32_ShadowCopy | ForEach-Object { $n = $_.DeviceObject.Split('\')[-1]; cmd /c copy /b /y "$($_.DeviceObject)\Windows\AppCompat\Programs\RecentFileCache.bcf" "C:\triage\RecentFileCache_$n.bcf" }Then drop the C:\triage folder (or the .bcf files) on this page. Several copies load side by side.
Needs: An elevated prompt on the host, with KAPE or Velociraptor on the host or a USB drive.
KAPE: RecentFileCache target
Raw read that keeps NTFS metadata; --vss also collects the copy inside every shadow copy.
kape.exe --tsource C: --tdest C:\triage\kape --target RecentFileCache --vssVelociraptor: Windows.Triage.Targets
In the Velociraptor GUI (Velociraptor Triage project artifact; formerly Windows.KapeFiles.Targets on older releases): Server Artifacts → Build offline collector → Windows.Triage.Targets → tick the RecentFileCache target → Launch, download the collector, run it as administrator on the host. From a server, collect the same artifact and target on the client and download the collection ZIP.
Drop the C:\triage\kape folder or the Velociraptor ZIP as-is: the ZIP is searched in your browser and only RecentFileCache.bcf is extracted.
Needs: Any OS. An image is read-only, so there is no lock to work around.
FTK Imager
File → Add Evidence Item → Image File, open the Windows partition, go to this path, right-click RecentFileCache.bcf → Export Files…
Windows\AppCompat\Programs\RecentFileCache.bcfImage mounted on Windows (Arsenal Image Mounter, FTK Imager Image Mounting…)
Replace E: with the drive letter of the mounted Windows volume. robocopy keeps the file's timestamps.
robocopy E:\Windows\AppCompat\Programs C:\triage RecentFileCache.bcfThe Sleuth Kit
mmls gives the NTFS partition's start sector (<offset>), fls the file's inode (<inode>, e.g. 12345-128-1); icat extracts it.
mmls image.dd
fls -r -p -o <offset> image.dd | grep -i RecentFileCache.bcf
icat -o <offset> image.dd <inode> > RecentFileCache.bcfDrop the exported RecentFileCache.bcf here. Export it from every shadow copy of the image too if your tool exposes them.
Needs: Windows 7 or Server 2008 R2 only.
Live system
Written by the Application Experience service (ProgramDataUpdater scheduled task).
C:\Windows\AppCompat\Programs\RecentFileCache.bcfInside each Volume Shadow Copy
N is the snapshot number. Older snapshots often keep entries the live file has lost.
\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy<N>\Windows\AppCompat\Programs\RecentFileCache.bcfWindows 8 and later: not present
Amcache.hve replaced it. This page tells you when a dropped collection only contains Amcache.hve.
No companion files needed. Drop one .bcf, several (one per host or snapshot), a whole folder or a ZIP: the file is found by its FE FF EE FF signature, whatever its name.
Gotchas
- A plain copy of the live file fails: it is held open. A 0-byte or all-zero copy means the copy failed, and this page says so.
- Windows 7 / Server 2008 R2 only. A Windows 8+ host has no RecentFileCache.bcf; collect Amcache.hve instead.
- Rewritten on every ProgramDataUpdater run and entries carry no timestamps: collect early, keep the shadow copies and the file's LastWriteTime.
Why analysts use it
The roll call Windows 7 kept, laid out for triage.
RecentFileCache.bcf is a list of program paths the Application Experience service noticed since its last sync. This workspace turns that list into something you can search, flag and hand over.
Drop the whole collection
A single .bcf, an extracted triage folder or a KAPE / Velociraptor ZIP. The file is found under Windows\AppCompat\Programs, and anything that isn't one is explained, not silently ignored.
Triage flags built in
Executables in Temp, user profiles, ProgramData, the Recycle Bin, other drive letters or network shares are flagged so the odd ones out surface first.
Built for long lists
A virtualized grid keeps thousands of rows smooth. Resize, fit or pin columns; search every path as you type.
A full-screen workspace
After the first file, results take over the window. Press Esc to get back to this page — your analysis stays open.
Sessions that survive a reload
The current analysis is auto-saved in this browser (IndexedDB). Name a session to keep it, then reopen, rename or delete it later.
Honest parsing
Header signature check, per-record offsets and character counts, warnings for truncated or trailing data, and a clean CSV or JSON export.
How it works
From acquisition to a flagged list in three steps.
- 01
Acquire
Copy C:\Windows\AppCompat\Programs\RecentFileCache.bcf with a raw reader or collect it with KAPE, plus every shadow copy.
- 02
Drop
Drop the file, the collection folder or its ZIP here. The parser runs in a Web Worker, entirely on your machine.
- 03
Triage and export
Filter flagged paths, bookmark the ones that matter, then export CSV or JSON for your timeline.
Questions analysts ask
Is my file uploaded anywhere?
No. The parser is Rust compiled to WebAssembly and runs in your browser. Files and saved sessions stay on this machine; nothing is sent to a server.
Which Windows versions have RecentFileCache.bcf?
Windows 7 and Windows Server 2008 R2. Windows 8 and later replaced it with Amcache.hve, so a ZIP from a Windows 10 host will usually not contain one — the workspace tells you when that is the case.
What can I drop?
A RecentFileCache.bcf file (any name — it is recognised by its signature), a folder, or a ZIP collection such as a KAPE or Velociraptor export using standard or Deflate compression. Several hosts or shadow copies can be loaded side by side.
Does an entry prove the program ran?
It shows the executable crossed the Application Experience code path since the last ProgramDataUpdater run — a strong lead, not a verdict. Entries carry no timestamps; corroborate with Prefetch, Amcache, ShimCache and event logs.
Where are saved sessions stored?
In this browser's IndexedDB storage. They include the .bcf files you loaded and your view (search, filters, bookmarks). Clearing site data removes them.
Related tools
Artifacts that answer the next question in the same case.
Blog
Read the blogGot a Windows 7 image on the bench?
Drop its RecentFileCache.bcf — or the whole collection — and get a flagged list in seconds.