Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Windows Capability Access Manager database parser #976

Open
qmadev opened this issue Dec 18, 2024 · 3 comments
Open

Windows Capability Access Manager database parser #976

qmadev opened this issue Dec 18, 2024 · 3 comments
Labels
enhancement New feature or request epic:windows capabilities good first issue Good for newcomers plugin Related to a plugin windows Related to Windows support/features

Comments

@qmadev
Copy link

qmadev commented Dec 18, 2024

The Capability Access Manager database is an artifact that stores information about which apps used which resources. An example would be which apps used the webcam or microphone. This database is present as of Windows 11.

References

@Horofic
Copy link
Contributor

Horofic commented Dec 19, 2024

Hey @qmadev thanks for creating this issue! Seems like a cool new artefact, and a good addition to Dissect. Is this something you are willing to contribute in the form of a Pull Request?

@Horofic Horofic added enhancement New feature or request good first issue Good for newcomers plugin Related to a plugin epic:windows capabilities windows Related to Windows support/features labels Dec 19, 2024
@qmadev
Copy link
Author

qmadev commented Dec 19, 2024

hey @Horofic, maybe in the future. I already submitted a PR for similar artefacts that reside in registry (#979). This database would need a separate parser.

@Horofic
Copy link
Contributor

Horofic commented Dec 19, 2024

Thank you for the initial PR, I will take a look at it tomorrow! As far as the separate parser goes, I took a cursory look at the link you provided. The database seems to be SQLite based, we have a separate project dissect.sql that is able to parse SQLite databases. This should help if you decide to pick up that part!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request epic:windows capabilities good first issue Good for newcomers plugin Related to a plugin windows Related to Windows support/features
Projects
None yet
Development

No branches or pull requests

2 participants