anyone know of an extension that exposes appcompat...
# extensions
anyone know of an extension that exposes appcompat/amcachehive entries as a table?
The Windows appcompat database? I don't know of an extension like that. Does Microsoft have an API to enumerate the AppCompat shims, or just the optional download for the Application Compatibility Toolkit?
Maybe you could use the existing osquery tables and read the keys “HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom” and “HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\InstalledSDB”
Or use the
table to watch for files created in the default shim database directories of “C:\Windows\AppPatch\Custom” and “C:\Windows\AppPatch\Custom\Custom64”
Oh wait I see there's already an
table in osquery
Appcompat/shimcache entries were just added to osquery