Skip to content

RDP Bitmap Cache Location and How to Acquire It

Where the RDP bitmap cache is stored for each user, and how to collect it with PowerShell, KAPE RDPCache, Velociraptor or from a disk image, without the usual gotchas.

Published on 6 min read

TL;DR. The RDP bitmap cache is in C:\Users\<user>\AppData\Local\Microsoft\Terminal Server Client\Cache\ on the machine the user connected from, one folder per account. Collect the whole folder for every user, keep the Users\<name>\ part of the path so each file stays attributed to its account, and close open Remote Desktop sessions first because the files can be in use. KAPE's RDPCache target and Velociraptor's Windows.Triage.Targets do this for you; a short PowerShell loop or a find on a mounted image works too.

For what the cache contains and why it matters, start with the RDP bitmap cache forensics guide.

Where the cache lives

The RDP bitmap cache is written by the Remote Desktop Connection client, mstsc, into the local (non-roaming) AppData of the user who ran it.

SystemPath
Current WindowsC:\Users\<user>\AppData\Local\Microsoft\Terminal Server Client\Cache\
Windows XPC:\Documents and Settings\<user>\Local Settings\Application Data\Microsoft\Terminal Server Client\Cache\
After an in-place upgradeC:\Windows.old\Users\<user>\AppData\Local\Microsoft\Terminal Server Client\Cache\

In that folder you can find two families of files:

FilesFormat
bcache2.bmc, bcache22.bmc, bcache24.bmcLegacy BMC cache, fixed slots, 8/16/32 bpp
Cache0000.bin, Cache0001.bin, ...RDP 8 persistent cache, 32-bit tiles

Both families can sit side by side in the same folder. Collect everything in it; do not filter by extension.

Which host, which user

Two mistakes cost the most time:

  • Wrong host. The cache records what the client displayed, so it is on the source host. If an attacker jumped from WKS-A to SRV-B, the evidence about the session on SRV-B is in the cache on WKS-A. It is worth collecting on the target too, but for sessions that started from the target.
  • Wrong account. The cache belongs to the account that ran mstsc, not the account used to log on to the remote host. A local svc_backup profile on the source can hold the screens of a session opened with domain credentials on the target.

That is why the path matters: RDP Bitmap Cache Parser attributes each file to the account taken from Users\<name>\ in the path. Strip the path and you lose the attribution.

Option 1: PowerShell on a live system

Run as administrator. Close open Remote Desktop sessions first.

Get-ChildItem C:\Users -Directory | ForEach-Object {
  $rel = "Users\$($_.Name)\AppData\Local\Microsoft\Terminal Server Client\Cache"
  if (Test-Path "C:\$rel") { robocopy "C:\$rel" "C:\triage\$rel" /E /B /R:0 /W:0 /NP /NDL /NFL | Out-Null }
}
tar -a -c -f C:\triage\rdpcache.zip -C C:\triage Users

What it does: for each profile folder, copy the Cache folder with robocopy in backup mode (/B), no retries, quiet output, and keep the Users\<name>\... structure under C:\triage. Then tar -a builds a ZIP from that structure. The ZIP can be dropped straight into the tool.

This loop only looks at C:\Users. It does not cover Windows.old or XP paths; use KAPE or a mounted image for those.

Option 2: KAPE

KapeFiles ships an RDPCache target (source). It collects the cache folder for every user, plus the Windows.old and Windows XP locations.

kape.exe --tsource C: --tdest C:\triage\kape --target RDPCache

KAPE keeps the original directory structure under the destination, so account attribution survives. Zip the destination folder, or drop it as a folder.

Option 3: Velociraptor

Collect Windows.Triage.Targets (from the Velociraptor Triage project) with the RDPCache target, either from the GUI against a live client or through an offline collector. The resulting collection ZIP can be loaded as is: the tool reads ZIPs, including those produced by KAPE and Velociraptor, and finds the cache files inside.

Option 4: a mounted disk image

With the Windows volume mounted read-only at /mnt/win:

cd /mnt/win && find Users -ipath '*/Terminal Server Client/Cache/*' -type f | zip -@ ~/triage/rdpcache.zip

-ipath is case-insensitive, which matters on images where the folder names vary in case. Adapt the start directory to Windows.old/Users or Documents and Settings for older layouts.

Gotchas

ProblemCauseFix
Copy fails or files are skippedA session is open and the client holds the filesClose sessions, or use backup mode / a raw-disk collector
Files attributed to nobodyPaths flattened during collectionKeep Users\<name>\... in the archive
Nothing for the account you expectedWrong host or wrong profileCheck which account ran mstsc on which host
Upgrade history missedWindows.old not collectedUse the KAPE target or search the image
Large archiveCache files can be tens of MB with thousands of tilesNormal; the tool processes them locally

Also collect the NTFS metadata ($MFT, $UsnJrnl) and the artifacts that date the sessions, since the tiles themselves carry no time: the RDP client event log, the user's NTUSER.DAT for the Terminal Server Client registry keys, jump lists and Prefetch. The list and how to use them are in RDP lateral movement: source host artifacts.

Scoping: which hosts to collect from

Collect from every host where someone may have started a Remote Desktop session during the period of interest, not only from the servers that were accessed. Good candidates are admin workstations, jump hosts, and any machine where the RDP client event log or the Terminal Server Client registry keys name a target in scope. A cache that turns out to be empty or old costs little; a missed source host can cost the only view of what happened on the target.

Integrity

Hash the archive or the files as collected, record the tool and command used, and work on copies. The browser tool only reads the bytes you give it and does not modify or upload them, but good practice does not depend on the tool.

Next step

Load the ZIP or folder into RDP Bitmap Cache Parser, or follow how to analyze the RDP bitmap cache in your browser step by step.

FAQ

Where is the RDP bitmap cache stored?

In each user's profile on the machine that ran the Remote Desktop client: C:\Users\<user>\AppData\Local\Microsoft\Terminal Server Client\Cache\. On Windows XP it is under Documents and Settings\<user>\Local Settings\Application Data. After an upgrade, also check C:\Windows.old\Users.

Why does my copy of the cache fail?

The files can be in use while a Remote Desktop session is open. Close the sessions first, or copy in backup mode (robocopy /B) or with a raw-disk collector such as KAPE or Velociraptor.

Does KAPE have a target for the RDP bitmap cache?

Yes. The KapeFiles target RDPCache collects the Cache folder for every user, including the Windows.old and Windows XP paths.

Related articles

Step-by-step: load bcache*.bmc and Cache*.bin files into a free in-browser parser, triage tiles, build a collage, rebuild a screen and export the evidence.
Which artifacts on the RDP source host show where a user connected and when, and how to use them to date and attribute what the bitmap cache shows.
Why an RDP cache collage lines up in places and drifts in others, how to pick the collage width, and how to rebuild a screen tile by tile on a canvas.