HomeSecurityNew AmCache EvilHunter tool for detecting malicious activities

New AmCache EvilHunter tool for detecting malicious activities

AmCache EvilHunter plays a decisive role in identifying malicious activities on Windows systems. This tool allows the identification of both benign and malicious software running on a computer.

See also: Cybercriminals imitate well-known brands to scam users

AmCache EvilHunter

Managed by the operating system and essentially immutable, AmCache data remains even when the malicious software self-deletes, making it irreplaceable in incident response.

AmCache EvilHunter stores SHA-1 hashes of executed files, allowing DFIR professionals to query public threat intelligence feeds such as OpenTIP and VirusTotal and quickly generate breach indicators for network-wide blocking.

The new open-source tool, released by Kaspersky, simplifies the analysis of the Amcache.hve, automating IOC extraction and threat intelligence searches to accelerate threat detection and isolation.

AmCache EvilHunter is a command-line tool written in Python that imports the file C:\Windows\AppCompat\Programs\Amcache.hve and extracts key metadata entries.

It analyzes critical registry keys such as InventoryApplicationFile , InventoryDriverBinary , InventoryApplication , and InventoryApplicationShortcut —to reveal file paths, publisher data, LinkDate timestamps , binary file types (32-bit vs. 64-bit), and SHA-1 hashes. An example run filters records by date range, exporting a CSV of all executables that exist between September 1 and September 30, 2025.

See also: Hackers exploit Dynamic DNS providers for malicious purposes

New AmCache EvilHunter tool for detecting malicious activities
New AmCache EvilHunter tool for detecting malicious activities

The FileID field contains the hash with four leading zeros, while the Size and IsOsComponent flags help analysts distinguish binaries from potential malicious software.

Kaspersky said that AmCache-EvilHunter features include threat intelligence integration and advanced filtering options. The –find-suspicious flag applies heuristics—such as single-letter names (1.exe), random hex names, and common typo variations like scvhost.exe —to flag anomalous entries.

Additional flags, –missing-publisher and –exclude-os, further reduce noise by filtering on signed elements of the operating system. For each recognized hash, users can perform automatic searches on VirusTotal and Kaspersky OpenTIP, adding detection numbers and threat classification tags to the output.

Analysts can also search for specific keywords or ProgramId values using –search “winscp.exe” to confirm the presence of deleted or temporary tools.

AmCache EvilHunter uses the Python Registry library to load the hive in REGF format while traversing its subkeys and values.

See also: Cybersecurity: 6 innovative ways to use AI

New AmCache EvilHunter tool for detecting malicious activities

Its modular architecture allows developers to extend support for custom IOC streams or integrate with SOAR platforms. The binaries and scripts are available on GitHub for development on both Windows and Linux.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS