Glossary
Plain-language definitions of the BAM/DAM and Windows registry terms used in our guides.
- Background Activity Moderator (BAM)
- A Windows 10 1709+ kernel driver (bam.sys) that throttles background apps and keeps a per-user list of executables with a timestamp in the SYSTEM hive.
- Control set (ControlSet00X)
- A numbered copy of the system configuration inside the SYSTEM hive; Select\Current says which one was in use. CurrentControlSet only exists on a live system.
- Desktop Activity Moderator (DAM)
- A Windows kernel driver that suspends or throttles desktop apps during connected (Modern) standby, and keeps BAM-style per-user records in the SYSTEM hive.
- Dirty hive
- A registry hive whose header sequence numbers differ, meaning some changes still live only in its .LOG1/.LOG2 transaction logs and must be replayed.
- Evidence of execution
- Forensic artifacts showing that a program ran on a system — BAM, Prefetch, Amcache, UserAssist, event logs — each with different scope, timing and reliability.
- FILETIME
- The 64-bit Windows timestamp counting 100-nanosecond intervals since 1 January 1601 UTC, used for BAM last-execution times and registry key times.
- Modern Standby (connected standby)
- A Windows low-power mode where the device stays on with the screen off. The Desktop Activity Moderator only loads, and records, on hardware that supports it.
- NT device path (\Device\HarddiskVolumeN)
- The kernel's native path form, such as \Device\HarddiskVolume3\Windows\System32\cmd.exe, used in BAM value names instead of drive letters.
- Package family name
- The identifier of a packaged (Store/MSIX) app, such as Microsoft.WindowsCalculator_8wekyb3d8bbwe, which BAM uses as the value name instead of a path.
- ProfileList
- The SOFTWARE hive key mapping each account SID to its profile folder via ProfileImagePath; used to put a user name next to BAM's SIDs.
- Security identifier (SID)
- The unique value Windows uses to identify an account or group, such as S-1-5-21-…-1001. BAM keeps one registry key per SID: that is how it attributes execution.
- SYSTEM hive
- The Windows registry hive file at C:\Windows\System32\config\SYSTEM that backs HKLM\SYSTEM: services, control sets, and the BAM and DAM keys.