Skip to content

Windows 7 · AppCompat · 100% local

RecentFileCache.bcf parser, in your browser.

Drop a Windows 7 RecentFileCache.bcf file and inspect its cached file paths. Parsing runs locally in WebAssembly — your evidence never leaves your machine.

  • No upload — WebAssembly in your browser
  • Drop a .bcf, a folder or a KAPE / Velociraptor ZIP
  • Saved sessions stay in this browser
  • CSV and JSON export

RecentFileCache parser

Drop a RecentFileCache.bcf, a triage folder or a KAPE / Velociraptor ZIP here, or click to choose.

Choose a file

Parsing runs 100% client-side via WebAssembly. The file is never uploaded.

Synthetic Windows 7 RecentFileCache.bcf from a fictional intrusion — no real data. This artifact only exists on Windows 7 / Server 2008 R2 (Amcache.hve replaced it on Windows 8+).

How to get your data

From a Windows 7 host to results in about two minutes. Take the first method that fits: every command is ready to paste.

  1. 1CollectRun one command on the host
  2. 2DropDrop the file, the C:\triage folder or the ZIP here
  3. 3Stays localParsed in your browser, never uploaded

Needs: Windows 7 or Server 2008 R2, PowerShell (the default 64-bit one) started with Run as administrator.

Current file, through a temporary shadow copy

The live file is held open, so this snapshots C:, copies RecentFileCache.bcf out of the snapshot into C:\triage, then deletes the snapshot.

PowerShell
New-Item -ItemType Directory -Force C:\triage | Out-Null
$s = ([wmiclass]'Win32_ShadowCopy').Create('C:\', 'ClientAccessible')
$sc = Get-WmiObject Win32_ShadowCopy -Filter "ID='$($s.ShadowID)'"
cmd /c copy /b /y "$($sc.DeviceObject)\Windows\AppCompat\Programs\RecentFileCache.bcf" C:\triage\RecentFileCache.bcf
$sc.Delete()

Also: older versions from existing shadow copies

Each snapshot holds its own copy, often with entries already purged from the live file. Saved as RecentFileCache_HarddiskVolumeShadowCopyN.bcf; snapshots of other drives just print "cannot find the path".

PowerShell
New-Item -ItemType Directory -Force C:\triage | Out-Null
Get-WmiObject Win32_ShadowCopy | ForEach-Object { $n = $_.DeviceObject.Split('\')[-1]; cmd /c copy /b /y "$($_.DeviceObject)\Windows\AppCompat\Programs\RecentFileCache.bcf" "C:\triage\RecentFileCache_$n.bcf" }

Then drop the C:\triage folder (or the .bcf files) on this page. Several copies load side by side.

Gotchas

  • A plain copy of the live file fails: it is held open. A 0-byte or all-zero copy means the copy failed, and this page says so.
  • Windows 7 / Server 2008 R2 only. A Windows 8+ host has no RecentFileCache.bcf; collect Amcache.hve instead.
  • Rewritten on every ProgramDataUpdater run and entries carry no timestamps: collect early, keep the shadow copies and the file's LastWriteTime.
Full acquisition guide →
Illustration with sample paths — not real evidence.

Why analysts use it

The roll call Windows 7 kept, laid out for triage.

RecentFileCache.bcf is a list of program paths the Application Experience service noticed since its last sync. This workspace turns that list into something you can search, flag and hand over.

Drop the whole collection

A single .bcf, an extracted triage folder or a KAPE / Velociraptor ZIP. The file is found under Windows\AppCompat\Programs, and anything that isn't one is explained, not silently ignored.

Triage flags built in

Executables in Temp, user profiles, ProgramData, the Recycle Bin, other drive letters or network shares are flagged so the odd ones out surface first.

Built for long lists

A virtualized grid keeps thousands of rows smooth. Resize, fit or pin columns; search every path as you type.

A full-screen workspace

After the first file, results take over the window. Press Esc to get back to this page — your analysis stays open.

Sessions that survive a reload

The current analysis is auto-saved in this browser (IndexedDB). Name a session to keep it, then reopen, rename or delete it later.

Honest parsing

Header signature check, per-record offsets and character counts, warnings for truncated or trailing data, and a clean CSV or JSON export.

How it works

From acquisition to a flagged list in three steps.

  1. 01

    Acquire

    Copy C:\Windows\AppCompat\Programs\RecentFileCache.bcf with a raw reader or collect it with KAPE, plus every shadow copy.

  2. 02

    Drop

    Drop the file, the collection folder or its ZIP here. The parser runs in a Web Worker, entirely on your machine.

  3. 03

    Triage and export

    Filter flagged paths, bookmark the ones that matter, then export CSV or JSON for your timeline.

Questions analysts ask

Is my file uploaded anywhere?

No. The parser is Rust compiled to WebAssembly and runs in your browser. Files and saved sessions stay on this machine; nothing is sent to a server.

Which Windows versions have RecentFileCache.bcf?

Windows 7 and Windows Server 2008 R2. Windows 8 and later replaced it with Amcache.hve, so a ZIP from a Windows 10 host will usually not contain one — the workspace tells you when that is the case.

What can I drop?

A RecentFileCache.bcf file (any name — it is recognised by its signature), a folder, or a ZIP collection such as a KAPE or Velociraptor export using standard or Deflate compression. Several hosts or shadow copies can be loaded side by side.

Does an entry prove the program ran?

It shows the executable crossed the Application Experience code path since the last ProgramDataUpdater run — a strong lead, not a verdict. Entries carry no timestamps; corroborate with Prefetch, Amcache, ShimCache and event logs.

Where are saved sessions stored?

In this browser's IndexedDB storage. They include the .bcf files you loaded and your view (search, filters, bookmarks). Clearing site data removes them.

Artifacts that answer the next question in the same case.

The BCF's lifecycle is one scheduled task. Understand when ProgramDataUpdater runs, when it clears the file, and how to spot a disabled appraiser.
The BCF format is a header, a list of length-prefixed UTF-16LE paths, and that's it. Here is what every byte means and why nothing has changed since 2009.
A SOC-flagged Win7 endpoint, 14 paths in the BCF, three worth a second look. A realistic corroboration chain and how much the BCF actually contributed.

Got a Windows 7 image on the bench?

Drop its RecentFileCache.bcf — or the whole collection — and get a flagged list in seconds.