Title
#extensions
v

Vijay

08/05/2020, 5:34 PM
anyone know of an extension that exposes appcompat/amcachehive entries as a table?
Mike Myers

Mike Myers

08/05/2020, 5:53 PM
The Windows appcompat database? I don't know of an extension like that. Does Microsoft have an API to enumerate the AppCompat shims, or just the optional download for the Application Compatibility Toolkit?
5:56 PM
Maybe you could use the existing osquery tables and read the keys “HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom” and “HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\InstalledSDB”
5:56 PM
Or use the
ntfs_journal_events
table to watch for files created in the default shim database directories of “C:\Windows\AppPatch\Custom” and “C:\Windows\AppPatch\Custom\Custom64”
5:57 PM
Oh wait I see there's already an
appcompat_shims
table in osquery https://osquery.io/schema/4.4.0/#appcompat_shims
puffycid

puffycid

08/06/2020, 12:00 AM