Skip to content

Glossary

Plain-language definitions of the BAM/DAM and Windows registry terms used in our guides.

Background Activity Moderator (BAM)
A Windows 10 1709+ kernel driver (bam.sys) that throttles background apps and keeps a per-user list of executables with a timestamp in the SYSTEM hive.
Control set (ControlSet00X)
A numbered copy of the system configuration inside the SYSTEM hive; Select\Current says which one was in use. CurrentControlSet only exists on a live system.
Desktop Activity Moderator (DAM)
A Windows kernel driver that suspends or throttles desktop apps during connected (Modern) standby, and keeps BAM-style per-user records in the SYSTEM hive.
Dirty hive
A registry hive whose header sequence numbers differ, meaning some changes still live only in its .LOG1/.LOG2 transaction logs and must be replayed.
Evidence of execution
Forensic artifacts showing that a program ran on a system — BAM, Prefetch, Amcache, UserAssist, event logs — each with different scope, timing and reliability.
FILETIME
The 64-bit Windows timestamp counting 100-nanosecond intervals since 1 January 1601 UTC, used for BAM last-execution times and registry key times.
Modern Standby (connected standby)
A Windows low-power mode where the device stays on with the screen off. The Desktop Activity Moderator only loads, and records, on hardware that supports it.
NT device path (\Device\HarddiskVolumeN)
The kernel's native path form, such as \Device\HarddiskVolume3\Windows\System32\cmd.exe, used in BAM value names instead of drive letters.
Package family name
The identifier of a packaged (Store/MSIX) app, such as Microsoft.WindowsCalculator_8wekyb3d8bbwe, which BAM uses as the value name instead of a path.
ProfileList
The SOFTWARE hive key mapping each account SID to its profile folder via ProfileImagePath; used to put a user name next to BAM's SIDs.
Security identifier (SID)
The unique value Windows uses to identify an account or group, such as S-1-5-21-…-1001. BAM keeps one registry key per SID: that is how it attributes execution.
SYSTEM hive
The Windows registry hive file at C:\Windows\System32\config\SYSTEM that backs HKLM\SYSTEM: services, control sets, and the BAM and DAM keys.