Skip to content

Glossary

ProfileList

The SOFTWARE hive key mapping each account SID to its profile folder via ProfileImagePath; used to put a user name next to BAM's SIDs.

ProfileList is the key SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList. Each subkey is named after a SID and has a ProfileImagePath value such as C:\Users\alice, pointing at that account's profile folder.

Forensic parsers, including the BAM/DAM Parser, use the last folder of that path as the account name for BAM keys. It is a strong hint rather than the authoritative name: Microsoft documents that renaming an account does not change its profile path. For local accounts, confirm with the SAM hive. More in BAM user attribution.