How to Analyze the RDP Bitmap Cache in Your Browser
Step-by-step: load bcache*.bmc and Cache*.bin files into a free in-browser parser, triage tiles, build a collage, rebuild a screen and export the evidence.
TL;DR. Collect Terminal Server Client\Cache for every user on the source host, drop the folder or ZIP on RDP Bitmap Cache Parser, read the Findings panel, then work through the tabs: Gallery (with Review first and Hide blank and duplicate tiles), Collage (adjust tiles per row), Reconstruct (place tiles on a grid) and List. Export CSV, JSON, a ZIP of PNG or bmc-tools-style BMP tiles, or the reconstructed screen. Decoding runs in WebAssembly inside your browser; the files are never uploaded.
This is the hands-on companion to the RDP bitmap cache forensics guide. The examples use the built-in sample, which is synthetic and fictional: it was generated for this tool and does not come from a real case.
Before you start
| You need | Why |
|---|---|
The Cache folder of each user, from the source host | That is where the client writes the cache |
The Users\<name>\ part of the path | The tool attributes each file to that account |
| A current desktop browser | Decoding runs as WebAssembly in a Web Worker |
| Optional: bmc-tools | To cross-check important tiles |
Step 1: Collect the cache folder
Close open Remote Desktop sessions, then copy the folder for every profile. The PowerShell loop the site shows:
Get-ChildItem C:\Users -Directory | ForEach-Object {
$rel = "Users\$($_.Name)\AppData\Local\Microsoft\Terminal Server Client\Cache"
if (Test-Path "C:\$rel") { robocopy "C:\$rel" "C:\triage\$rel" /E /B /R:0 /W:0 /NP /NDL /NFL | Out-Null }
}
tar -a -c -f C:\triage\rdpcache.zip -C C:\triage Users
KAPE (--target RDPCache), Velociraptor (Windows.Triage.Targets with the RDPCache target) and a mounted image work too; see RDP bitmap cache location and acquisition. Hash what you collected.
Step 2: Load the files
Open the tool home page. You can drop:
- individual files (
bcache*.bmc,Cache*.bin); - a folder, for example a copied profile;
- a ZIP: KAPE and Velociraptor collections and zipped profiles are opened in the browser.
To learn the interface first, click Try a sample. The workspace goes full screen automatically; press Esc to leave it.
The sample contains two files from a fictional profile svc_backup: Cache0000.bin (32 bpp, 47 tiles) and bcache22.bmc (16 bpp, 15 tiles, 10 of them RLE-compressed).
Step 3: Read the Findings panel
Before looking at a single tile, read the summary:
- Accounts that used the RDP client, from the paths.
- Console-like tiles: where commands may be readable.
- Slot remnants: fragments of older tiles in
.bmcslots (slot remnant). - Undecodable tiles, if any.
- The reminder that tiles have no timestamps. The tool shows no time range and does not invent one; date the sessions with source host artifacts.
Step 4: Triage the gallery
The Gallery tab shows each tile with its index in cache order. Two controls do most of the work:
| Control | Effect |
|---|---|
| Hide blank and duplicate tiles | Removes single-colour tiles and tiles identical to an earlier one |
| Review first | Keeps console-like and text-like tiles |
The triage hints are heuristics:
| Hint | Meaning |
|---|---|
| Console-like | Text-like content on a dark background; commands may be readable |
| Text-like | Flat background with many sharp edges |
| Slot remnant | Leftover of an older tile in a .bmc slot |
| Blank | A single colour |
| Duplicate | Identical to an earlier tile |
| Not decoded | The tile could not be decoded |
They can miss tiles and flag harmless ones. They tell you what is worth reading first, nothing more. In the sample, Review first brings up the console tiles with the rclone.exe copy command and the earlier tar -xf tools.zip -C C:\ProgramData\Intel view.
Step 5: Inspect a tile
Click a tile to open its detail: cache key, width and height, bit depth, compression (interleaved RLE or none), file offset and triage hint. The offset lets you check the tile in a hex editor. A single tile can be exported as PNG for your notes.
For 8-bit tiles, remember the colours are approximate: the palette is not stored in the cache.
Step 6: Build a collage
The Collage tab lays out all tiles in one image. Set the number of tiles per row and pick a layout: Cache order (tile 0 at top-left) or bmc-tools layout (the same arrangement as bmc-tools' collage, for side-by-side comparison).
In the sample, set 7 tiles per row. The middle rows (tiles 7–20) line up and the rclone command reads across; the first and last rows drift, because identical pieces were cached once. Reconstructing RDP screens from cache tiles explains the effect. Export the collage as PNG.
Step 7: Reconstruct a screen
The Reconstruct tab is a grid. Drag a tile onto a cell, or select a tile and click a cell. Place the lined-up rows first, then fill the title bar and the empty console areas by reusing the same tile in several cells. Leave cells empty when you are not sure.
Export the canvas as PNG and the layout JSON, which records which tile went where. Put both in the case file so a reviewer can check your placement.
Step 8: Export the evidence
| Export | Contents |
|---|---|
| CSV / JSON | The tile inventory with its metadata |
| ZIP of tiles | Every tile as PNG, or as BMP named like bmc-tools output (<file>_<NNNN>.bmp), plus a tiles.csv inside |
| Single tile PNG, collage PNG | For the report |
| Reconstruct PNG + layout JSON | The rebuilt screen and how it was built |
The BMP naming lets you feed the tiles to tools built around bmc-tools output, such as RdpCacheStitcher. The List tab gives a list view of the tiles.
Limits to keep in mind
- No OCR and no automatic stitching: you read and place the tiles.
- Tiles narrower than 64 pixels use their own width as row stride; bmc-tools assumes 64, so narrow tiles can differ between tools.
- The decoder is an independent implementation (Microsoft MS-RDPBCGR and MS-RDPEGDI, plus public research), validated tile by tile against ANSSI's bmc-tools on synthetic and hand-built files. On real cases, compare important tiles with bmc-tools; see RDP cache parsers compared.
RDP Bitmap Cache Parser is an independent project, not affiliated with or endorsed by Microsoft.