Skip to content

Series

BAM/DAM fundamentals

6 posts in this series. Read them in order or jump to any one.

  1. BAM/DAM Forensics: The Complete Guide to Windows BAM

    What the Windows Background Activity Moderator records, where BAM and DAM live in the SYSTEM hive, what they prove, what they miss, and how to read them.

  2. BAM Registry Key: Where It Is and How to Collect It

    The exact BAM and DAM registry paths per Windows build, why CurrentControlSet doesn't exist offline, and how to acquire SYSTEM with its transaction logs.

  3. BAM Value Data Format: FILETIME, Paths and Internals

    Byte-level walkthrough of a BAM registry value: the 24-byte REG_BINARY, the FILETIME, device paths vs package names, Version, SequenceNumber and key times.

  4. BAM Across Windows Versions: 1709, 1809, 11 and Server

    Which Windows builds have BAM and DAM, where the key moved in 1809, what an upgraded host looks like, and what to check on Windows 11 and Windows Server.

  5. Desktop Activity Moderator (DAM) Forensics Explained

    What the Desktop Activity Moderator is, why its registry key is empty on most desktops, how DAM entries differ from BAM, and how to use them on laptops.

  6. BAM Limitations and Anti-Forensics: What BAM Misses

    Seven-day pruning, deleted executables, removable and network paths, console tools, dirty hives and tampering: every known BAM blind spot and how to detect it.

All posts in this series