Parity item (feature-parity.md). USB Detective reads Amcache.hve InventoryDevicePnp entries for execution/first-seen corroboration.
Blocker: no fleet reader decodes Amcache (checked peripheral-core/-forensic, winreg-core/-forensic), and no real Amcache.hve USB corpus is on hand. Per ADR-0002 the parsing belongs in a fleet crate (an amcache-core on winreg-core), then usb-forensic wires it like the other registry sources.
To unblock: (1) build/adopt an Amcache reader crate; (2) source a real Amcache.hve with USB device entries + ground truth (regipy oracle).
Parity item (feature-parity.md). USB Detective reads
Amcache.hveInventoryDevicePnp entries for execution/first-seen corroboration.Blocker: no fleet reader decodes Amcache (checked peripheral-core/-forensic, winreg-core/-forensic), and no real
Amcache.hveUSB corpus is on hand. Per ADR-0002 the parsing belongs in a fleet crate (anamcache-coreonwinreg-core), then usb-forensic wires it like the other registry sources.To unblock: (1) build/adopt an Amcache reader crate; (2) source a real Amcache.hve with USB device entries + ground truth (regipy oracle).