SOLFIND
Web Lens
Portal home

WinSearchAppCache/AppCacheParse.py at main · dfirdetective/WinSearchAppCache · GitHub

https://github.com/dfirdetective/WinSearchAppCache/blob/main/AppCacheParse.py • 267 KB fetched
Open original page


WinSearchAppCache/AppCacheParse.py at main · dfirdetective/WinSearchAppCache · GitHub

Skip to content

Navigation Menu

Sign in Appearance settings

* Platform
* AI CODE CREATION
* GitHub Copilot Write better code with AI

* GitHub Copilot app Direct agents from issue to merge

* MCP Registry Integrate external tools

* DEVELOPER WORKFLOWS
* Actions Automate any workflow

* Codespaces Instant dev environments

* Issues Plan and track work

* Code Review Manage code changes

* Code Quality Enforce quality at merge

* APPLICATION SECURITY
* GitHub Advanced Security Find and fix vulnerabilities

* Code security Secure your code as you build

* Secret protection Stop leaks before they start

* EXPLORE
* Why GitHub

* Documentation

* Blog

* Changelog

* Marketplace

View all features

* Solutions
* BY COMPANY SIZE
* Enterprises

* Small and medium teams

* Startups

* Nonprofits

* BY USE CASE
* App Modernization

* DevSecOps

* DevOps

* CI/CD

* View all use cases

* BY INDUSTRY
* Healthcare

* Financial services

* Manufacturing

* Government

* View all industries

View all solutions

* Resources
* EXPLORE BY TOPIC
* AI

* Software Development

* DevOps

* Security

* View all topics

* EXPLORE BY TYPE
* Customer stories

* Events & webinars

* Ebooks & reports

* Business insights

* GitHub Skills

* SUPPORT & SERVICES
* Documentation

* Customer support

* Community forum

* Trust center

* Partners

View all resources

* Open Source
* COMMUNITY
* GitHub Sponsors Fund open source developers

* PROGRAMS
* Security Lab

* Maintainer Community

* GitHub Stars

* Archive Program

* REPOSITORIES
* Topics

* Trending

* Collections

* Enterprise
* ENTERPRISE SOLUTIONS
* Enterprise platform AI-powered developer platform

* AVAILABLE ADD-ONS
* GitHub Advanced Security Enterprise-grade security features

* Copilot for Business Enterprise-grade AI features

* Premium Support Enterprise-grade 24/7 support

* Pricing
Search /

Sign in
Sign up Appearance settings

You signed in with another tab or window. Reload to refresh your session.
You signed out in another tab or window. Reload to refresh your session.
You switched accounts on another tab or window. Reload to refresh your session.

Dismiss alert

dfirdetective

/

WinSearchAppCache

Public

*
Notifications
You must be signed in to change notification settings

*
Fork
5

*

Star
10

*

Code

*

Issues
0

*

Pull requests
0

*

Actions

*

Projects

*

Security and quality
0

*

Insights

Additional navigation options

*

Code

*

Issues

*

Pull requests

*

Actions

*

Projects

*

Security and quality

*

Insights

Files Expand file tree

main

Breadcrumbs

* WinSearchAppCache
/ AppCacheParse.py

Copy path

Blame
More file actions

Blame
More file actions

Latest commit
 

History
History
History

114 lines (98 loc) · 4.38 KB

main

Breadcrumbs

* WinSearchAppCache
/ AppCacheParse.py

Copy path

Top

File metadata and controls

* Code

* Blame

114 lines (98 loc) · 4.38 KB

Raw
Copy raw file
Download raw file

Open symbols panel Edit and raw actions

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114

"""

AppCacheParse.py v3

Author: Cassie Doemel

Intent: AppCacheXXXXXXXXXXXXXXXXXX.txt to csv for readability for my research

Current Iteration: Collects and parses artifact from host Windows machine.

Run from your desired output directory. Will create WinSearchAppCache folder

with subdirectory of the POSIX timestamp at run time. Directory will contain

raw AppCache file, SettingsCache file, and the two Output.csv parsed data files.

Future TODO: Create CLI args to allow for parse-only or mounted directory selection.

"""

from pathlib import Path

import json

import csv

import os

import shutil

from datetime import datetime

homeDir = Path.home()

p = str(homeDir)

dt = datetime.now()

ts = datetime.timestamp(dt)

appCacheLoc = p + '\\AppData\\Local\\Packages\\Microsoft.Windows.Search_cw5n1h2txyewy\\LocalState\\DeviceSearchCache'

outputPath = Path.cwd() / 'WinSearchAppCache' / str(ts)

# TODO create command-line arguments to run against whatever you want.

def acfile_exists(file):

with open(file, encoding='utf=8') as appCache:

data = json.load(appCache)

outputFile = str(outputPath) + "\\" + file.stem + "-Output.csv"

cacheOutput = open(outputFile, 'w') # Creates the output file

csv_writer = csv.writer(cacheOutput)

count = 0

for d in data:

if count == 0: # Writes the 0 row as headers

header = list(d.keys())

acwritehead = []

for x in header:

if x[0:7] == "System.":

y = x[7:]

acwritehead.append(y)

csv_writer.writerow(acwritehead)

count += 1

dValues = list(d.values())

dData = []

for item in dValues: # Writes the rest as values

for v in item.keys():

if v.startswith("Value"): # Strips off "Type: "

# if v.islist, iterate over list in some way to clean it up?

# .strip(\r\n

dData.append(item[v])

csv_writer.writerow(dData)

print("Parsed data printed to " + outputFile)

appCache.close() # Closes the file so it can be viewed.

def scfile_exists(file):

with open(file, encoding='utf=8') as scCache:

data = json.load(scCache)

outputFile = str(outputPath) + "\\" + file.stem + "-Output.csv"

cacheOutput = open(outputFile, 'w') # Creates the output file

csv_writer = csv.writer(cacheOutput)

count = 0

try:

for d in data:

if count == 0: # Writes the 0 row as headers

scwritehead = ['ParsingName', 'ActivationContext', 'SmallLogoPath', 'PageID', 'SettingID',

'HostID', 'Condition', 'Comment', 'HighKeywords']

csv_writer.writerow(scwritehead)

count += 1

dValues = list(d.values())

dData = []

for item in dValues: # Writes the rest as values

for v in item.keys():

if v.startswith("Value"): # Strips off "Type: "

dData.append(item[v])

csv_writer.writerow(dData)

except UnicodeError:

print("Error: File closed incomplete due to Unicode error.") # Repeated fails on Defender line

print("Parsed data printed to " + outputFile)

scCache.close() # Closes the file so it can be viewed.

def find_app_cache():

try:

shutil.copytree(appCacheLoc, outputPath) # Copies AppCache & SettingsCache

print("Host folder copied to " + str(outputPath))

for folderName, subfolders, filenames in os.walk(outputPath):

for filename in filenames:

cachefile = Path(outputPath) / filename

if "AppCache" in filename:

acfile_exists(cachefile)

else:

scfile_exists(cachefile)

except Exception as inst:

print(type(inst), " - ", inst.args)

def target_host():

if str(homeDir.anchor)[0].isalpha(): # checking for root drive letter to ID as Windows

find_app_cache()

else:

print("This is intended to target the host Windows machine by locating root drive at this time.")

print("Running WinSearchAppCache... Start time: ", dt)

target_host()

dt = datetime.now()

print("WinSearchAppCache Complete! End time: ", dt)

Footer

(c) 2026 GitHub, Inc.

Footer navigation

*
Terms

*
Privacy

*
Security

*
Status

*
Community

*
Docs

*
Contact

*

Manage cookies

*

Do not share my personal information

You can’t perform that action at this time.

Links found on this page

  1. Skip to content [direct]
  2. Sign in [direct]
  3. GitHub Copilot Write better code with AI [direct]
  4. GitHub Copilot app Direct agents from issue to merge [direct]
  5. MCP Registry Integrate external tools [direct]
  6. Actions Automate any workflow [direct]
  7. Codespaces Instant dev environments [direct]
  8. Issues Plan and track work [direct]
  9. Code Review Manage code changes [direct]
  10. Code Quality Enforce quality at merge [direct]
  11. GitHub Advanced Security Find and fix vulnerabilities [direct]
  12. Code security Secure your code as you build [direct]
  13. Secret protection Stop leaks before they start [direct]
  14. Why GitHub [direct]
  15. Documentation [direct]
  16. Blog [direct]
  17. Changelog [direct]
  18. Marketplace [direct]
  19. View all features [direct]
  20. Enterprises [direct]
  21. Small and medium teams [direct]
  22. Startups [direct]
  23. Nonprofits [direct]
  24. App Modernization [direct]
  25. DevSecOps [direct]
  26. DevOps [direct]
  27. CI/CD [direct]
  28. View all use cases [direct]
  29. Healthcare [direct]
  30. Financial services [direct]
  31. Manufacturing [direct]
  32. Government [direct]
  33. View all industries [direct]
  34. View all solutions [direct]
  35. AI [direct]
  36. Software Development [direct]
  37. DevOps [direct]
  38. Security [direct]
  39. View all topics [direct]
  40. Customer stories [direct]
  41. Events & webinars [direct]
  42. Ebooks & reports [direct]
  43. Business insights [direct]
  44. GitHub Skills [direct]
  45. Customer support [direct]
  46. Community forum [direct]
  47. Trust center [direct]
  48. Partners [direct]
  49. View all resources [direct]
  50. GitHub Sponsors Fund open source developers [direct]
  51. Security Lab [direct]
  52. Maintainer Community [direct]
  53. GitHub Stars [direct]
  54. Archive Program [direct]
  55. Topics [direct]
  56. Trending [direct]
  57. Collections [direct]
  58. Copilot for Business Enterprise-grade AI features [direct]
  59. Premium Support Enterprise-grade 24/7 support [direct]
  60. Pricing [direct]
  61. Sign up [direct]
  62. dfirdetective [direct]
  63. WinSearchAppCache [direct]
  64. Notifications [direct]
  65. Issues 0 [direct]
  66. Pull requests 0 [direct]
  67. Actions [direct]
  68. Projects [direct]
  69. Security and quality 0 [direct]
  70. Insights [direct]
  71. WinSearchAppCache [direct]
  72. History [direct]
  73. Raw [direct]
  74. Terms [direct]
  75. Privacy [direct]
  76. Security [direct]
  77. Status [direct]
  78. Community [direct]
  79. Contact [direct]