What is the RDP bitmap cache?
To avoid downloading the same screen pieces again, the Remote Desktop client (mstsc.exe) keeps a persistent cache of small bitmaps — usually 64×64-pixel tiles — sent by the remote machine. The files stay in the profile of the user who ran the client.
Put back together, the tiles show fragments of what that user saw on the remote screen: consoles and the commands in them, folder windows, tools, documents. For an investigator that is rare, visual evidence of lateral movement, collected on the source machine.
Where it is stored
- C:\Users\<user>\AppData\Local\Microsoft\Terminal Server Client\Cache\ on the machine the connection was made from.
- Cache0000.bin, Cache0001.bin…: newer format, a "RDP8bmp" header then uncompressed 32-bit tiles.
- bcache2.bmc, bcache22.bmc, bcache24.bmc: legacy format, fixed 64×64 slots at 8, 16 or 32 bits per pixel, tiles often compressed with the RDP interleaved RLE codec.
Why it matters in an investigation
- Shows what an attacker or administrator actually looked at on the remote host — even when that host was wiped or never imaged.
- Console tiles can reveal commands, paths and tool names; explorer tiles reveal folder and file names.
- Its presence alone proves the account used the Remote Desktop client on this machine; correlate with the client event log and registry to name the target and date the sessions.
- Legacy slots can keep fragments of older tiles (slot remnants).
Limitations
- Tiles have no timestamps and no screen position: the order is cache order, and identical tiles are stored once.
- Only what the server sent as bitmaps is cached; some sessions leave few usable tiles, and the cache is capped in size and recycled.
- 8-bit legacy tiles lack their palette, so colours are approximate. There is no OCR: tiles must be read by a human.
- Heuristic hints (console-like, text-like) can miss tiles or flag harmless ones.
How to get the files
- Collect the whole Cache folder of every profile with KAPE (RDPCache target), Velociraptor (Windows.Triage.Targets, RDPCache) or from a disk image.
- Record the files' timestamps: they are the main clue to when sessions happened.
- Keep the Users\<name>\ folder structure so each cache is attributed to its account.
FAQ
Are my cache files uploaded anywhere?
No. The decoder is Rust compiled to WebAssembly and runs in a Web Worker in your browser. There is no upload endpoint; tiles, collages and exports are built locally.
How is this different from bmc-tools?
It has its own decoder, written independently from Microsoft's specifications and validated against bmc-tools, then adds what is hard on the command line: a searchable gallery, collage settings you can change instantly, a drag-and-drop reconstruction canvas, triage hints and exports (PNG, BMP with bmc-tools names, CSV, JSON). bmc-tools remains the reference to cross-check important findings.
Can it tell me when a tile was displayed?
No — the cache stores no time per tile, and this tool does not invent one. Date the sessions with the cache files' timestamps, the RDPClient/Operational event log (event 1024) and the Terminal Server Client registry keys.
Which machine holds the cache?
The client: the machine where Remote Desktop Connection ran, in the profile of the user who launched it. It shows the remote screen, so an attacker's pivot from host A to host B leaves B's screen fragments on A.
Why do my collage rows not line up?
Tiles are stored in the order they were cached, identical tiles only once, and edge tiles are smaller. Try other widths, then finish by hand in the Reconstruct view.
About the decoder
The decoder is an independent Rust implementation written from Microsoft's open specifications ([MS-RDPBCGR] for Interleaved RLE, [MS-RDPEGDI] for the RDP 6.0 planar codec) and public research such as the CERT-FR bulletin CERTFR-2016-ACT-017. ANSSI's bmc-tools (github.com/ANSSI-FR/bmc-tools), the reference tool for this artifact, was used to validate the output tile by tile; none of its code is used. Documented differences: tiles narrower than 64 px keep their real width, decompressed 8 and 32 bpp tiles keep their real colour depth, RDP 6.0 planar tiles are decoded, and damaged files are decoded as far as possible. Compare with bmc-tools on important cases.