anyone know of an extension that exposes appcompat/amcachehive entries as a table?
08/05/2020, 5:53 PM
The Windows appcompat database? I don't know of an extension like that. Does Microsoft have an API to enumerate the AppCompat shims, or just the optional download for the Application Compatibility Toolkit?
Maybe you could use the existing osquery tables and read the keys “HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom” and “HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\InstalledSDB”
Or use the
table to watch for files created in the default shim database directories of “C:\Windows\AppPatch\Custom” and “C:\Windows\AppPatch\Custom\Custom64”