مضى على الشبكة و يوم من العطاء.

مسارات مهمة في (Registry) للتحليل الجنائي الرقمي - part (3)

H4x0r

./ عضو

السمعة:

Important Registry Paths for Forensic Analysis​

No.Registry PathDescription
1HKLM\SYSTEM\CurrentControlSet\Control\ComputerNameComputer name
2HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\UninstallInstalled software
3HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocsRecent documents
4HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRURecently opened/saved files
5HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRURun history
6HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\ParametersNetwork configuration
7HKCU\Software\Microsoft\Internet Explorer\TypedURLsTyped URLs in Internet Explorer
8HKCU\Software\Microsoft\Windows\CurrentVersion\Internet SettingsInternet settings
9HKLM\SYSTEM\CurrentControlSet\Services\bam\UserSettingsRecently executed programs
10HKCU\Software\Microsoft\OfficeMicrosoft Office usage
11HKLM\SYSTEM\CurrentControlSet\Enum\USBUSB device history
12HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2Mounted devices
13HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WinlogonWinlogon settings
14HKLM\SYSTEM\CurrentControlSet\Control\TimeZoneInformationTime zone information
15HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssistUserAssist data
16HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileListUser profile paths
17HKCU\Control Panel\DesktopDesktop settings
18HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell FoldersUser-specific folders
19HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Group PolicyGroup policy settings
20HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Memory ManagementMemory management settings
21HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WindowsWindows folder paths
22HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\ExplorerUser-specific policies
23HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\ProfilesNetwork profiles
24HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExtsFile extension actions
25HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32System drivers
26HKCU\Software\Microsoft\Search Assistant\ACMruSearch Assistant history
27HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AeDebugDebugger settings
28HKCU\Software\Microsoft\Windows\CurrentVersion\Applets\RegeditLast key viewed in Regedit
29HKLM\SYSTEM\CurrentControlSet\Control\SafeBootSafe boot options
30HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRUFolder settings
31HKCU\Software\Microsoft\Terminal Server ClientRemote desktop connections
32HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PerflibPerformance library
33HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\AdvancedExplorer advanced settings
34HKLM\SYSTEM\CurrentControlSet\Control\Print\PrintersConfigured printers
35HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows Messaging SubsystemMessaging settings
36HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIconsHidden desktop icons
37HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotfixInstalled hotfixes
38HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\WallpapersWallpaper history
39HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\EMDMgmtExternal device management
40HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ReliabilitySystem reliability data
41HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffectsVisual effects settings
42HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\VirtualizationVirtualization settings
43HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSIDExplorer CLSID data
44HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WindowsUpdateWindows Update settings
45HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\TrayNotifyTray notifications
46HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WOWWindows on Windows settings
47HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPageStart page settings
48HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WinPEWindows Preinstallation Environment
49HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\TaskbandTaskbar settings
50HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileGuidUser profile GUIDs
51HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell ExtensionsShell extensions
52HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfoSession information
53HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\MMDevicesMultimedia devices
54HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\DiscardableDiscardable post-setup data
55HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\LogonUILogon UI settings
56HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage2Start page settings (alternate)
57HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WSMANWindows Remote Management
58HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrderMenu order settings
59HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\UninstallUninstalled software
60HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRUStream MRU
61HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper ObjectsBrowser Helper Objects (BHOs)
62HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskSchedulerShared task scheduler
63HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooksShell execute hooks
64HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellStateShell state
65HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiersShell icon overlay identifiers
66HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocsRecent documents (alternate)
67HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NamespaceMy Computer namespace
68HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanelHidden desktop icons in new start panel
69HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\DriveIconsDrive icons
70HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedMRULast visited MRU
71HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\BitBucketRecycle bin settings
72HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\AdvancedAdvanced explorer settings
73HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskSchedulerShared task scheduler (alternate)
74HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell FoldersShell folders
75HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell FoldersSystem shell folders
76HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocsRecent documents (alternate)
77HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\RecentDocsSystem recent documents
78HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NamespaceUser-specific My Computer namespace
79HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenuHidden desktop icons in classic start menu
80HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenuUser-specific hidden desktop icons in classic start menu
81HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel\NamespaceControl Panel namespace
82HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel\NamespaceUser-specific Control Panel namespace
83HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ControlPanelControl Panel settings
84HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSIDCLSID data
85HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\CLSIDSystem CLSID data
86HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\AdvancedAdvanced explorer settings (alternate)
87HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AdvancedSystem advanced explorer settings
88HKCU\Software\Microsoft\Windows\CurrentVersion\ExplorerUser-specific explorer settings
89HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ExplorerSystem explorer settings
90HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZonesInternet security zones
91HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZonesSystem internet security zones
92HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMapInternet zone map
93HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMapSystem internet zone map
94HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\DomainsInternet zone map domains
95HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\DomainsSystem internet zone map domains
96HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\RangesInternet zone map ranges
97HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\RangesSystem internet zone map ranges
98HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaultsInternet protocol defaults
99HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaultsSystem internet protocol defaults
100HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ConnectionsInternet connections settings

Important Registry Paths for Offensive Security and Red Teaming​

No.Registry PathDescription
1HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunPrograms that run on system startup
2HKCU\Software\Microsoft\Windows\CurrentVersion\RunPrograms that run on user login
3HKLM\SYSTEM\CurrentControlSet\ServicesSystem services
4HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WinlogonWinlogon process customization
5HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\RunUser-specific startup programs
6HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\RunSystem-wide startup programs
7HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution OptionsDebugger settings for executables
8HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoadDelayed loading of shell extensions
9HKCU\Software\Microsoft\Office\<version>\Outlook\SecurityOutlook security settings
10HKLM\SYSTEM\CurrentControlSet\Control\LsaLocal Security Authority settings
11HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\UninstallInstalled software
12HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2Mounted devices
13HKLM\SYSTEM\CurrentControlSet\Control\SafeBootSafe boot options
14HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRUFolder settings
15HKCU\Software\Microsoft\Terminal Server ClientRemote desktop connections
16HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PerflibPerformance library
17HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32System drivers
18HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AeDebugDebugger settings
19HKCU\Software\Microsoft\Windows\CurrentVersion\Applets\RegeditLast key viewed in Regedit
20HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper ObjectsBrowser Helper Objects (BHOs)
21HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooksShell execute hooks
22HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiersShell icon overlay identifiers
23HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NamespaceMy Computer namespace
24HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\DriveIconsDrive icons
25HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\BitBucketRecycle bin settings
26HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskSchedulerShared task scheduler
27HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell FoldersSystem shell folders
28HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\RecentDocsSystem recent documents
29HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenuHidden desktop icons in classic start menu
30HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel\NamespaceControl Panel namespace
31HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ControlPanelControl Panel settings
32HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\CLSIDSystem CLSID data
33HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AdvancedSystem advanced explorer settings
34HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ExplorerSystem explorer settings
35HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZonesSystem internet security zones
36HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMapSystem internet zone map
37HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\DomainsSystem internet zone map domains
38HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\RangesSystem internet zone map ranges
39HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaultsSystem internet protocol defaults
40HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ConnectionsInternet connections settings
41HKLM\SYSTEM\CurrentControlSet\Control\ComputerNameComputer name
42HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRURecently opened/saved files
43HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRURun history
44HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\ParametersNetwork configuration
45HKCU\Software\Microsoft\Internet Explorer\TypedURLsTyped URLs in Internet Explorer
46HKCU\Software\Microsoft\Windows\CurrentVersion\Internet SettingsInternet settings
47HKLM\SYSTEM\CurrentControlSet\Services\bam\UserSettingsRecently executed programs
48HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocsRecent documents
49HKLM\SYSTEM\CurrentControlSet\Enum\USBUSB device history
50HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileListUser profile paths
51HKCU\Control Panel\DesktopDesktop settings
52HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell FoldersUser-specific folders
53HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Group PolicyGroup policy settings
54HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Memory ManagementMemory management settings
55HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WindowsWindows folder paths
56HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\ExplorerUser-specific policies
57HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\ProfilesNetwork profiles
58HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExtsFile extension actions
59HKCU\Software\Microsoft\Search Assistant\ACMruSearch Assistant history
60HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellStateShell state
61HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocsRecent documents (alternate)
62HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanelHidden desktop icons in new start panel
63HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedMRULast visited MRU
64HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\AdvancedAdvanced explorer settings
65HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell FoldersShell folders
66HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocsRecent documents (alternate)
67HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NamespaceUser-specific My Computer namespace
68HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenuUser-specific hidden desktop icons in classic start menu
69HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel\NamespaceUser-specific Control Panel namespace
70HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSIDCLSID data
71HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\AdvancedAdvanced explorer settings (alternate)
72HKCU\Software\Microsoft\Windows\CurrentVersion\ExplorerUser-specific explorer settings
73HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZonesInternet security zones
74HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMapInternet zone map
75HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\DomainsInternet zone map domains
76HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\RangesInternet zone map ranges
77HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaultsInternet protocol defaults
78HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell ExtensionsShell extensions
79HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfoSession information
80HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\MMDevicesMultimedia devices
81HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\DiscardableDiscardable post-setup data
82HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\LogonUILogon UI settings
83HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage2Start page settings (alternate)
84HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WSMANWindows Remote Management
85HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrderMenu order settings
86HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRUStream MRU
87HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskSchedulerShared task scheduler
88HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellStateShell state
89HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocsRecent documents (alternate)
90HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanelHidden desktop icons in new start panel
91HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedMRULast visited MRU
92HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\AdvancedAdvanced explorer settings
93HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell FoldersShell folders
94HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocsRecent documents (alternate)
95HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\NamespaceUser-specific My Computer namespace
96HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenuUser-specific hidden desktop icons in classic start menu
97HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel\NamespaceUser-specific Control Panel namespace
98HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSIDCLSID data
99HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\AdvancedAdvanced explorer settings (alternate)
100HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer
 
التعديل الأخير:

آخر المشاركات

عودة
أعلى