Skip to content

RDP Cache Parsers Compared: bmc-tools and Alternatives

bmc-tools, RdpCacheStitcher and RDP Bitmap Cache Parser side by side: what each does, where each fits in a case, and the honest limits of the browser tool.

Published on 6 min read

TL;DR. bmc-tools (ANSSI, Python) is the reference decoder for the RDP bitmap cache and the one to cite. RdpCacheStitcher (BSI) is a GUI that helps you stitch tiles exported by bmc-tools into screens. RDP Bitmap Cache Parser decodes the same files in the browser, with its own independently written decoder, validated against bmc-tools, plus a gallery with triage hints, a collage, a reconstruction canvas and exports. It is not a replacement for a second opinion: on real cases, compare important tiles with bmc-tools.

If you are choosing a tool because you just found a Terminal Server Client\Cache folder, the RDP bitmap cache forensics guide explains what you are looking at.

The three tools at a glance

bmc-toolsRdpCacheStitcherRDP Bitmap Cache Parser
MaintainerANSSI (France)BSI (Germany)Independent (this site)
FormPython command-line scriptDesktop GUIWeb page, WebAssembly in a Web Worker
Inputbcache*.bmc, Cache*.binTiles exported by bmc-toolsbcache*.bmc, Cache*.bin, folders, ZIPs
DecodingYes (reference)No, uses exported tilesYes (independent, validated against bmc-tools)
CollageYes (-b, width -w)Not its purposeYes, configurable, two layouts
Screen reconstructionNoYes, its purposeManual canvas
Slot remnantsExported with -oWorks on exported tilesShown and flagged
InstallPythonDownloadNone
LicenseCeCILL 2.1See its repositoryFree to use

We describe RdpCacheStitcher only as far as we are sure; read its repository and manual for its full feature set.

bmc-tools

bmc-tools is the reference implementation. Much of the public work on this artifact relies on its reverse engineering of the BMC and Cache*.bin formats. Our own decoder is a separate implementation, written from Microsoft's protocol specifications (MS-RDPBCGR and MS-RDPEGDI) and CERT-FR's public description of the files (bulletin CERTFR-2016-ACT-017), and validated tile by tile against bmc-tools. Tile decompression (interleaved RLE) has been supported since version 3.00 in 2022.

Options:

OptionPurpose
-sSource file or folder
-dDestination folder
-cNumber of tiles to extract
-vVerbose output
-o / --oldAlso export old data in slots (remnants)
-bBuild a collage bitmap
-wCollage width in tiles per row (default 64)
-kKAPE-style output folders

Output: one BMP per tile named <file>_<NNNN>.bmp, and <file>_collage.bmp when a collage is requested.

Strengths: the reference behaviour, scriptable, easy to run across many collections, citable. Trade-offs: a Python environment on the analysis machine, and you then browse hundreds or thousands of BMP files in an image viewer.

RdpCacheStitcher

RdpCacheStitcher, published by the BSI, is a GUI that helps you stitch exported tiles into screens. It takes the tiles exported by bmc-tools as input. Use it when the job is rebuilding full screens and you want a dedicated desktop application for that.

Strengths: purpose-built for reconstruction. Trade-offs: it is a second step after bmc-tools, and a desktop install.

RDP Bitmap Cache Parser

The tool on this site decodes both formats in the browser. Files never leave the machine: decoding runs in Rust compiled to WebAssembly, in a Web Worker.

What it adds around the decoder:

  • Intake of files, folders and ZIPs (KAPE, Velociraptor, zipped profiles), with each file attributed to the account from Users\<name>\ in the path.
  • Findings panel: accounts that used the RDP client, console-like tiles, slot remnants, undecodable tiles, and a reminder that tiles carry no timestamps.
  • Gallery with tile index and cache order, triage hints (Console-like, Text-like, Slot remnant, Blank, Duplicate, Not decoded), a Review first filter and Hide blank and duplicate tiles.
  • Collage with configurable tiles per row, in Cache order or bmc-tools layout to match bmc-tools' _collage.bmp arrangement.
  • Reconstruct: a grid canvas to place tiles by hand, exported as PNG plus a layout JSON.
  • Tile detail: key, size, depth, compression, file offset.
  • Exports: CSV, JSON, a ZIP of tiles as PNG or as BMP named like bmc-tools output (with a tiles.csv), single tile PNG, collage PNG.

Honest limits

LimitWhat to do
No OCRRead text yourself; transcribe it in notes
No automatic stitchingPlace tiles by hand on the Reconstruct canvas, or use RdpCacheStitcher
Heuristic hints can miss or over-flagTreat them as reading order, not findings
8-bit colours approximateThe palette is not in the cache; rely on shapes and text
Narrow tiles decoded with their own width as row stridebmc-tools assumes 64; compare the two on narrow tiles
Decompressed 8- and 32-bit tiles shown at their real depth; planar 32-bit tiles decodedbmc-tools renders decompressed tiles as 16-bit and skips planar ones; expect differences on those tiles
Validated on synthetic and hand-built filesCross-check important tiles with bmc-tools on real cases
Runs in a browser tabVery large collections depend on the browser's memory

The tool shows no time range because the cache holds no times. Dating is done with source host artifacts.

Which one when

SituationSuggested tool
Quick look at a cache folder on an analysis laptop without PythonRDP Bitmap Cache Parser
Batch processing many collections in a pipelinebmc-tools
Rebuilding full screens with a dedicated desktop toolbmc-tools, then RdpCacheStitcher
Triage: which tiles should I read first?RDP Bitmap Cache Parser (Review first)
A finding that goes into a reportDecode with two tools and compare
Sharing tiles with a colleague using bmc-tools workflowsRDP Bitmap Cache Parser BMP ZIP (bmc-tools naming)

The tools combine well. One workable path: triage in the browser, export the BMP ZIP, then reconstruct in RdpCacheStitcher or on the Reconstruct canvas, and re-run bmc-tools on the originals for the tiles you cite.

Verifying one tool against another

For a tile you plan to cite:

  1. Note its index and file offset in the tile detail panel.
  2. Run bmc-tools on the same file and open the corresponding BMP (match by index, and by content if the numbering differs).
  3. Compare the images. Differences are most likely on narrow tiles (row stride), 8-bit tiles (palette), decompressed 8- and 32-bit tiles (bmc-tools renders them as 16-bit) and planar 32-bit tiles, which bmc-tools skips.
  4. Record both in your notes.

For a walkthrough of the browser workflow, see how to analyze the RDP bitmap cache in your browser.

Related articles

Step-by-step: load bcache*.bmc and Cache*.bin files into a free in-browser parser, triage tiles, build a collage, rebuild a screen and export the evidence.
Which artifacts on the RDP source host show where a user connected and when, and how to use them to date and attribute what the bitmap cache shows.
Why an RDP cache collage lines up in places and drifts in others, how to pick the collage width, and how to rebuild a screen tile by tile on a canvas.