Skip to content

RDP bitmap cache · field notes

Blog

Articles, guides, and updates.

Step-by-step: load bcache*.bmc and Cache*.bin files into a free in-browser parser, triage tiles, build a collage, rebuild a screen and export the evidence.
Which artifacts on the RDP source host show where a user connected and when, and how to use them to date and attribute what the bitmap cache shows.
Why an RDP cache collage lines up in places and drifts in others, how to pick the collage width, and how to rebuild a screen tile by tile on a canvas.
bmc-tools, RdpCacheStitcher and RDP Bitmap Cache Parser side by side: what each does, where each fits in a case, and the honest limits of the browser tool.
Byte-level layout of the RDP bitmap cache: bcache*.bmc slots and 20-byte headers, interleaved RLE, pixel depths, slot remnants, and the RDP8bmp Cache*.bin format.
Where the RDP bitmap cache is stored for each user, and how to collect it with PowerShell, KAPE RDPCache, Velociraptor or from a disk image, without the usual gotchas.
What the RDP bitmap cache is, where it lives, what its tiles can show about a remote session, how to date it, and how to parse bcache*.bmc and Cache*.bin files.