Skip to content

How to Analyze the RDP Bitmap Cache in Your Browser

Step-by-step: load bcache*.bmc and Cache*.bin files into a free in-browser parser, triage tiles, build a collage, rebuild a screen and export the evidence.

Published on 6 min read

TL;DR. Collect Terminal Server Client\Cache for every user on the source host, drop the folder or ZIP on RDP Bitmap Cache Parser, read the Findings panel, then work through the tabs: Gallery (with Review first and Hide blank and duplicate tiles), Collage (adjust tiles per row), Reconstruct (place tiles on a grid) and List. Export CSV, JSON, a ZIP of PNG or bmc-tools-style BMP tiles, or the reconstructed screen. Decoding runs in WebAssembly inside your browser; the files are never uploaded.

This is the hands-on companion to the RDP bitmap cache forensics guide. The examples use the built-in sample, which is synthetic and fictional: it was generated for this tool and does not come from a real case.

Before you start

You needWhy
The Cache folder of each user, from the source hostThat is where the client writes the cache
The Users\<name>\ part of the pathThe tool attributes each file to that account
A current desktop browserDecoding runs as WebAssembly in a Web Worker
Optional: bmc-toolsTo cross-check important tiles

Step 1: Collect the cache folder

Close open Remote Desktop sessions, then copy the folder for every profile. The PowerShell loop the site shows:

Get-ChildItem C:\Users -Directory | ForEach-Object {
  $rel = "Users\$($_.Name)\AppData\Local\Microsoft\Terminal Server Client\Cache"
  if (Test-Path "C:\$rel") { robocopy "C:\$rel" "C:\triage\$rel" /E /B /R:0 /W:0 /NP /NDL /NFL | Out-Null }
}
tar -a -c -f C:\triage\rdpcache.zip -C C:\triage Users

KAPE (--target RDPCache), Velociraptor (Windows.Triage.Targets with the RDPCache target) and a mounted image work too; see RDP bitmap cache location and acquisition. Hash what you collected.

Step 2: Load the files

Open the tool home page. You can drop:

  • individual files (bcache*.bmc, Cache*.bin);
  • a folder, for example a copied profile;
  • a ZIP: KAPE and Velociraptor collections and zipped profiles are opened in the browser.

To learn the interface first, click Try a sample. The workspace goes full screen automatically; press Esc to leave it.

The sample contains two files from a fictional profile svc_backup: Cache0000.bin (32 bpp, 47 tiles) and bcache22.bmc (16 bpp, 15 tiles, 10 of them RLE-compressed).

Step 3: Read the Findings panel

Before looking at a single tile, read the summary:

  • Accounts that used the RDP client, from the paths.
  • Console-like tiles: where commands may be readable.
  • Slot remnants: fragments of older tiles in .bmc slots (slot remnant).
  • Undecodable tiles, if any.
  • The reminder that tiles have no timestamps. The tool shows no time range and does not invent one; date the sessions with source host artifacts.

The Gallery tab shows each tile with its index in cache order. Two controls do most of the work:

ControlEffect
Hide blank and duplicate tilesRemoves single-colour tiles and tiles identical to an earlier one
Review firstKeeps console-like and text-like tiles

The triage hints are heuristics:

HintMeaning
Console-likeText-like content on a dark background; commands may be readable
Text-likeFlat background with many sharp edges
Slot remnantLeftover of an older tile in a .bmc slot
BlankA single colour
DuplicateIdentical to an earlier tile
Not decodedThe tile could not be decoded

They can miss tiles and flag harmless ones. They tell you what is worth reading first, nothing more. In the sample, Review first brings up the console tiles with the rclone.exe copy command and the earlier tar -xf tools.zip -C C:\ProgramData\Intel view.

Step 5: Inspect a tile

Click a tile to open its detail: cache key, width and height, bit depth, compression (interleaved RLE or none), file offset and triage hint. The offset lets you check the tile in a hex editor. A single tile can be exported as PNG for your notes.

For 8-bit tiles, remember the colours are approximate: the palette is not stored in the cache.

Step 6: Build a collage

The Collage tab lays out all tiles in one image. Set the number of tiles per row and pick a layout: Cache order (tile 0 at top-left) or bmc-tools layout (the same arrangement as bmc-tools' collage, for side-by-side comparison).

In the sample, set 7 tiles per row. The middle rows (tiles 7–20) line up and the rclone command reads across; the first and last rows drift, because identical pieces were cached once. Reconstructing RDP screens from cache tiles explains the effect. Export the collage as PNG.

Step 7: Reconstruct a screen

The Reconstruct tab is a grid. Drag a tile onto a cell, or select a tile and click a cell. Place the lined-up rows first, then fill the title bar and the empty console areas by reusing the same tile in several cells. Leave cells empty when you are not sure.

Export the canvas as PNG and the layout JSON, which records which tile went where. Put both in the case file so a reviewer can check your placement.

Step 8: Export the evidence

ExportContents
CSV / JSONThe tile inventory with its metadata
ZIP of tilesEvery tile as PNG, or as BMP named like bmc-tools output (<file>_<NNNN>.bmp), plus a tiles.csv inside
Single tile PNG, collage PNGFor the report
Reconstruct PNG + layout JSONThe rebuilt screen and how it was built

The BMP naming lets you feed the tiles to tools built around bmc-tools output, such as RdpCacheStitcher. The List tab gives a list view of the tiles.

Limits to keep in mind

  • No OCR and no automatic stitching: you read and place the tiles.
  • Tiles narrower than 64 pixels use their own width as row stride; bmc-tools assumes 64, so narrow tiles can differ between tools.
  • The decoder is an independent implementation (Microsoft MS-RDPBCGR and MS-RDPEGDI, plus public research), validated tile by tile against ANSSI's bmc-tools on synthetic and hand-built files. On real cases, compare important tiles with bmc-tools; see RDP cache parsers compared.

RDP Bitmap Cache Parser is an independent project, not affiliated with or endorsed by Microsoft.

Related articles

bmc-tools, RdpCacheStitcher and RDP Bitmap Cache Parser side by side: what each does, where each fits in a case, and the honest limits of the browser tool.
Which artifacts on the RDP source host show where a user connected and when, and how to use them to date and attribute what the bitmap cache shows.
Why an RDP cache collage lines up in places and drifts in others, how to pick the collage width, and how to rebuild a screen tile by tile on a canvas.