RDP Cache Parsers Compared: bmc-tools and Alternatives
bmc-tools, RdpCacheStitcher and RDP Bitmap Cache Parser side by side: what each does, where each fits in a case, and the honest limits of the browser tool.
TL;DR. bmc-tools (ANSSI, Python) is the reference decoder for the RDP bitmap cache and the one to cite. RdpCacheStitcher (BSI) is a GUI that helps you stitch tiles exported by bmc-tools into screens. RDP Bitmap Cache Parser decodes the same files in the browser, with its own independently written decoder, validated against bmc-tools, plus a gallery with triage hints, a collage, a reconstruction canvas and exports. It is not a replacement for a second opinion: on real cases, compare important tiles with bmc-tools.
If you are choosing a tool because you just found a Terminal Server Client\Cache folder, the RDP bitmap cache forensics guide explains what you are looking at.
The three tools at a glance
| bmc-tools | RdpCacheStitcher | RDP Bitmap Cache Parser | |
|---|---|---|---|
| Maintainer | ANSSI (France) | BSI (Germany) | Independent (this site) |
| Form | Python command-line script | Desktop GUI | Web page, WebAssembly in a Web Worker |
| Input | bcache*.bmc, Cache*.bin | Tiles exported by bmc-tools | bcache*.bmc, Cache*.bin, folders, ZIPs |
| Decoding | Yes (reference) | No, uses exported tiles | Yes (independent, validated against bmc-tools) |
| Collage | Yes (-b, width -w) | Not its purpose | Yes, configurable, two layouts |
| Screen reconstruction | No | Yes, its purpose | Manual canvas |
| Slot remnants | Exported with -o | Works on exported tiles | Shown and flagged |
| Install | Python | Download | None |
| License | CeCILL 2.1 | See its repository | Free to use |
We describe RdpCacheStitcher only as far as we are sure; read its repository and manual for its full feature set.
bmc-tools
bmc-tools is the reference implementation. Much of the public work on this artifact relies on its reverse engineering of the BMC and Cache*.bin formats. Our own decoder is a separate implementation, written from Microsoft's protocol specifications (MS-RDPBCGR and MS-RDPEGDI) and CERT-FR's public description of the files (bulletin CERTFR-2016-ACT-017), and validated tile by tile against bmc-tools. Tile decompression (interleaved RLE) has been supported since version 3.00 in 2022.
Options:
| Option | Purpose |
|---|---|
-s | Source file or folder |
-d | Destination folder |
-c | Number of tiles to extract |
-v | Verbose output |
-o / --old | Also export old data in slots (remnants) |
-b | Build a collage bitmap |
-w | Collage width in tiles per row (default 64) |
-k | KAPE-style output folders |
Output: one BMP per tile named <file>_<NNNN>.bmp, and <file>_collage.bmp when a collage is requested.
Strengths: the reference behaviour, scriptable, easy to run across many collections, citable. Trade-offs: a Python environment on the analysis machine, and you then browse hundreds or thousands of BMP files in an image viewer.
RdpCacheStitcher
RdpCacheStitcher, published by the BSI, is a GUI that helps you stitch exported tiles into screens. It takes the tiles exported by bmc-tools as input. Use it when the job is rebuilding full screens and you want a dedicated desktop application for that.
Strengths: purpose-built for reconstruction. Trade-offs: it is a second step after bmc-tools, and a desktop install.
RDP Bitmap Cache Parser
The tool on this site decodes both formats in the browser. Files never leave the machine: decoding runs in Rust compiled to WebAssembly, in a Web Worker.
What it adds around the decoder:
- Intake of files, folders and ZIPs (KAPE, Velociraptor, zipped profiles), with each file attributed to the account from
Users\<name>\in the path. - Findings panel: accounts that used the RDP client, console-like tiles, slot remnants, undecodable tiles, and a reminder that tiles carry no timestamps.
- Gallery with tile index and cache order, triage hints (Console-like, Text-like, Slot remnant, Blank, Duplicate, Not decoded), a Review first filter and Hide blank and duplicate tiles.
- Collage with configurable tiles per row, in Cache order or bmc-tools layout to match bmc-tools'
_collage.bmparrangement. - Reconstruct: a grid canvas to place tiles by hand, exported as PNG plus a layout JSON.
- Tile detail: key, size, depth, compression, file offset.
- Exports: CSV, JSON, a ZIP of tiles as PNG or as BMP named like bmc-tools output (with a
tiles.csv), single tile PNG, collage PNG.
Honest limits
| Limit | What to do |
|---|---|
| No OCR | Read text yourself; transcribe it in notes |
| No automatic stitching | Place tiles by hand on the Reconstruct canvas, or use RdpCacheStitcher |
| Heuristic hints can miss or over-flag | Treat them as reading order, not findings |
| 8-bit colours approximate | The palette is not in the cache; rely on shapes and text |
| Narrow tiles decoded with their own width as row stride | bmc-tools assumes 64; compare the two on narrow tiles |
| Decompressed 8- and 32-bit tiles shown at their real depth; planar 32-bit tiles decoded | bmc-tools renders decompressed tiles as 16-bit and skips planar ones; expect differences on those tiles |
| Validated on synthetic and hand-built files | Cross-check important tiles with bmc-tools on real cases |
| Runs in a browser tab | Very large collections depend on the browser's memory |
The tool shows no time range because the cache holds no times. Dating is done with source host artifacts.
Which one when
| Situation | Suggested tool |
|---|---|
| Quick look at a cache folder on an analysis laptop without Python | RDP Bitmap Cache Parser |
| Batch processing many collections in a pipeline | bmc-tools |
| Rebuilding full screens with a dedicated desktop tool | bmc-tools, then RdpCacheStitcher |
| Triage: which tiles should I read first? | RDP Bitmap Cache Parser (Review first) |
| A finding that goes into a report | Decode with two tools and compare |
| Sharing tiles with a colleague using bmc-tools workflows | RDP Bitmap Cache Parser BMP ZIP (bmc-tools naming) |
The tools combine well. One workable path: triage in the browser, export the BMP ZIP, then reconstruct in RdpCacheStitcher or on the Reconstruct canvas, and re-run bmc-tools on the originals for the tiles you cite.
Verifying one tool against another
For a tile you plan to cite:
- Note its index and file offset in the tile detail panel.
- Run bmc-tools on the same file and open the corresponding BMP (match by index, and by content if the numbering differs).
- Compare the images. Differences are most likely on narrow tiles (row stride), 8-bit tiles (palette), decompressed 8- and 32-bit tiles (bmc-tools renders them as 16-bit) and planar 32-bit tiles, which bmc-tools skips.
- Record both in your notes.
For a walkthrough of the browser workflow, see how to analyze the RDP bitmap cache in your browser.