RDP Bitmap Cache Location and How to Acquire It
Where the RDP bitmap cache is stored for each user, and how to collect it with PowerShell, KAPE RDPCache, Velociraptor or from a disk image, without the usual gotchas.
TL;DR. The RDP bitmap cache is in C:\Users\<user>\AppData\Local\Microsoft\Terminal Server Client\Cache\ on the machine the user connected from, one folder per account. Collect the whole folder for every user, keep the Users\<name>\ part of the path so each file stays attributed to its account, and close open Remote Desktop sessions first because the files can be in use. KAPE's RDPCache target and Velociraptor's Windows.Triage.Targets do this for you; a short PowerShell loop or a find on a mounted image works too.
For what the cache contains and why it matters, start with the RDP bitmap cache forensics guide.
Where the cache lives
The RDP bitmap cache is written by the Remote Desktop Connection client, mstsc, into the local (non-roaming) AppData of the user who ran it.
| System | Path |
|---|---|
| Current Windows | C:\Users\<user>\AppData\Local\Microsoft\Terminal Server Client\Cache\ |
| Windows XP | C:\Documents and Settings\<user>\Local Settings\Application Data\Microsoft\Terminal Server Client\Cache\ |
| After an in-place upgrade | C:\Windows.old\Users\<user>\AppData\Local\Microsoft\Terminal Server Client\Cache\ |
In that folder you can find two families of files:
| Files | Format |
|---|---|
bcache2.bmc, bcache22.bmc, bcache24.bmc | Legacy BMC cache, fixed slots, 8/16/32 bpp |
Cache0000.bin, Cache0001.bin, ... | RDP 8 persistent cache, 32-bit tiles |
Both families can sit side by side in the same folder. Collect everything in it; do not filter by extension.
Which host, which user
Two mistakes cost the most time:
- Wrong host. The cache records what the client displayed, so it is on the source host. If an attacker jumped from
WKS-AtoSRV-B, the evidence about the session onSRV-Bis in the cache onWKS-A. It is worth collecting on the target too, but for sessions that started from the target. - Wrong account. The cache belongs to the account that ran
mstsc, not the account used to log on to the remote host. A localsvc_backupprofile on the source can hold the screens of a session opened with domain credentials on the target.
That is why the path matters: RDP Bitmap Cache Parser attributes each file to the account taken from Users\<name>\ in the path. Strip the path and you lose the attribution.
Option 1: PowerShell on a live system
Run as administrator. Close open Remote Desktop sessions first.
Get-ChildItem C:\Users -Directory | ForEach-Object {
$rel = "Users\$($_.Name)\AppData\Local\Microsoft\Terminal Server Client\Cache"
if (Test-Path "C:\$rel") { robocopy "C:\$rel" "C:\triage\$rel" /E /B /R:0 /W:0 /NP /NDL /NFL | Out-Null }
}
tar -a -c -f C:\triage\rdpcache.zip -C C:\triage Users
What it does: for each profile folder, copy the Cache folder with robocopy in backup mode (/B), no retries, quiet output, and keep the Users\<name>\... structure under C:\triage. Then tar -a builds a ZIP from that structure. The ZIP can be dropped straight into the tool.
This loop only looks at C:\Users. It does not cover Windows.old or XP paths; use KAPE or a mounted image for those.
Option 2: KAPE
KapeFiles ships an RDPCache target (source). It collects the cache folder for every user, plus the Windows.old and Windows XP locations.
kape.exe --tsource C: --tdest C:\triage\kape --target RDPCache
KAPE keeps the original directory structure under the destination, so account attribution survives. Zip the destination folder, or drop it as a folder.
Option 3: Velociraptor
Collect Windows.Triage.Targets (from the Velociraptor Triage project) with the RDPCache target, either from the GUI against a live client or through an offline collector. The resulting collection ZIP can be loaded as is: the tool reads ZIPs, including those produced by KAPE and Velociraptor, and finds the cache files inside.
Option 4: a mounted disk image
With the Windows volume mounted read-only at /mnt/win:
cd /mnt/win && find Users -ipath '*/Terminal Server Client/Cache/*' -type f | zip -@ ~/triage/rdpcache.zip
-ipath is case-insensitive, which matters on images where the folder names vary in case. Adapt the start directory to Windows.old/Users or Documents and Settings for older layouts.
Gotchas
| Problem | Cause | Fix |
|---|---|---|
| Copy fails or files are skipped | A session is open and the client holds the files | Close sessions, or use backup mode / a raw-disk collector |
| Files attributed to nobody | Paths flattened during collection | Keep Users\<name>\... in the archive |
| Nothing for the account you expected | Wrong host or wrong profile | Check which account ran mstsc on which host |
| Upgrade history missed | Windows.old not collected | Use the KAPE target or search the image |
| Large archive | Cache files can be tens of MB with thousands of tiles | Normal; the tool processes them locally |
Also collect the NTFS metadata ($MFT, $UsnJrnl) and the artifacts that date the sessions, since the tiles themselves carry no time: the RDP client event log, the user's NTUSER.DAT for the Terminal Server Client registry keys, jump lists and Prefetch. The list and how to use them are in RDP lateral movement: source host artifacts.
Scoping: which hosts to collect from
Collect from every host where someone may have started a Remote Desktop session during the period of interest, not only from the servers that were accessed. Good candidates are admin workstations, jump hosts, and any machine where the RDP client event log or the Terminal Server Client registry keys name a target in scope. A cache that turns out to be empty or old costs little; a missed source host can cost the only view of what happened on the target.
Integrity
Hash the archive or the files as collected, record the tool and command used, and work on copies. The browser tool only reads the bytes you give it and does not modify or upload them, but good practice does not depend on the tool.
Next step
Load the ZIP or folder into RDP Bitmap Cache Parser, or follow how to analyze the RDP bitmap cache in your browser step by step.
FAQ
Where is the RDP bitmap cache stored?
In each user's profile on the machine that ran the Remote Desktop client: C:\Users\<user>\AppData\Local\Microsoft\Terminal Server Client\Cache\. On Windows XP it is under Documents and Settings\<user>\Local Settings\Application Data. After an upgrade, also check C:\Windows.old\Users.
Why does my copy of the cache fail?
The files can be in use while a Remote Desktop session is open. Close the sessions first, or copy in backup mode (robocopy /B) or with a raw-disk collector such as KAPE or Velociraptor.
Does KAPE have a target for the RDP bitmap cache?
Yes. The KapeFiles target RDPCache collects the Cache folder for every user, including the Windows.old and Windows XP paths.