HKEY_CURREN_USER\Software\Classes for settings of interactive userHKEY_LOCAL_MACHINE\Software\Classes to change default settingsC:\Windows\System32\Config
HKEY_USERS\DEFAULTHKEY_LOCAL_MACHINE\SAMHKEY_LOCAL_MACHINE\SecurityHKEY_LOCAL_MACHINE\SoftwareHKEY_LOCAL_MACHINE\SystemC:\Users\<username>\
HKEY_CURRENT_USER , hidden fileC:\Users\<username>\AppData\Local\Microsoft\Windows
HKEY_CURRENT_USER\Sofware\CLASSES, hidden fileC:\Windows\AppCompat\Programs\Amcache.hve
<name of registry hive>.LOG of the registry hiveC:\Windows\System32\Config, as the hive which was altered.C:\Windows\System32\Config\RegBackAmcache.hveRegistry ViewerZimmerman's Registry Explorer, uses transaction logs as wellAppCompatCache ParserRegRipper, cli and guiSOFTWARE\Microsoft\Windows NT\CurrentVersionSYSTEM\CurrentControlSet\Control\ComputerName\ComputerNameSYSTEM\CurrentControlSet\Control\TimeZoneInformationSYSTEM\CurrentControlSet\Services\Tcpip\Parameters\InterfacesSOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\Signatures\Unmanaged and SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\Signatures\ManagedSYSTEM\CurrentControlSet\Servicesstart key value 0x02SAM\Domains\Account\UsersControlSet001 -> last bootControlSet002 -> last known goodHKLM\SYSTEM\CurrentControlSet -> live
Can be found under:
SYSTEM\Select\Current shows the used control setSYSTEM\Select\LastKnownGoodNTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\RunNTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\RunOnceSOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceSOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\RunSOFTWARE\Microsoft\Windows\CurrentVersion\RunNTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs, e.g. xml, pdf, jpgNTUSER.DAT\Software\Microsoft\Office\VERSION, NTUSER.DAT\Software\Microsoft\Office\15.0\WordNTUSER.DAT\Software\Microsoft\Office\VERSION\UserMRU\LiveID_####\FileMRUUSRCLASS.DAT\Local Settings\Software\Microsoft\Windows\Shell\BagsUSRCLASS.DAT\Local Settings\Software\Microsoft\Windows\Shell\BagMRUNTUSER.DAT\Software\Microsoft\Windows\Shell\BagMRUNTUSER.DAT\Software\Microsoft\Windows\Shell\BagsNTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePIDlMRUNTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedPidlMRUNTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Explorer\TypedPathsNTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Explorer\WordWheelQueryNTUSER.DAT\Software\Microsoft\Windows\Currentversion\Explorer\UserAssist\{GUID}\CountSYSTEM\CurrentControlSet\Control\Session Manager\AppCompatCacheAppCompatCacheParser.exe --csv <path to save output> -f <path to SYSTEM hive for data parsing> -c <control set to parse>C:\Windows\appcompat\Programs\Amcache.hveAmcache.hve\Root\File\{Volume GUID}\SYSTEM\CurrentControlSet\Services\bam\UserSettings\{SID}SYSTEM\CurrentControlSet\Services\dam\UserSettings\{SID}SYSTEM\CurrentControlSet\Enum\USBTOR, SYSTEM\CurrentControlSet\Enum\USBSOFTWARE\Microsoft\Windows Portable Devices\DevicesSYSTEM\CurrentControlSet\Enum\USBSTOR\Ven_Prod_Version\USBSerial#\Properties\{83da6326-97a6-4088-9453-a19231573b29}\0064SYSTEM\CurrentControlSet\Enum\USBSTOR\Ven_Prod_Version\USBSerial#\Properties\{83da6326-97a6-4088-9453-a19231573b29}\0066SYSTEM\CurrentControlSet\Enum\USBSTOR\Ven_Prod_Version\USBSerial#\Properties\{83da6326-97a6-4088-9453-a19231573b29}\0067
Social_engineering