HKEY_CURREN_USER\Software\Classes
for settings of interactive userHKEY_LOCAL_MACHINE\Software\Classes
to change default settingsC:\Windows\System32\Config
HKEY_USERS\DEFAULT
HKEY_LOCAL_MACHINE\SAM
HKEY_LOCAL_MACHINE\Security
HKEY_LOCAL_MACHINE\Software
HKEY_LOCAL_MACHINE\System
C:\Users\<username>\
HKEY_CURRENT_USER
, hidden fileC:\Users\<username>\AppData\Local\Microsoft\Windows
HKEY_CURRENT_USER\Sofware\CLASSES
, hidden fileC:\Windows\AppCompat\Programs\Amcache.hve
<name of registry hive>.LOG
of the registry hiveC:\Windows\System32\Config
, as the hive which was altered.C:\Windows\System32\Config\RegBack
Amcache.hve
Registry Viewer
Zimmerman's Registry Explorer
, uses transaction logs as wellAppCompatCache Parser
RegRipper
, cli and guiSOFTWARE\Microsoft\Windows NT\CurrentVersion
SYSTEM\CurrentControlSet\Control\ComputerName\ComputerName
SYSTEM\CurrentControlSet\Control\TimeZoneInformation
SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces
SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\Signatures\Unmanaged
and SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\Signatures\Managed
SYSTEM\CurrentControlSet\Services
start
key value 0x02
SAM\Domains\Account\Users
ControlSet001
-> last bootControlSet002
-> last known goodHKLM\SYSTEM\CurrentControlSet
-> live
Can be found under:
SYSTEM\Select\Current
shows the used control setSYSTEM\Select\LastKnownGood
NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Run
NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\RunOnce
SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run
SOFTWARE\Microsoft\Windows\CurrentVersion\Run
NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs
, e.g. xml, pdf, jpgNTUSER.DAT\Software\Microsoft\Office\VERSION
, NTUSER.DAT\Software\Microsoft\Office\15.0\Word
NTUSER.DAT\Software\Microsoft\Office\VERSION\UserMRU\LiveID_####\FileMRU
USRCLASS.DAT\Local Settings\Software\Microsoft\Windows\Shell\Bags
USRCLASS.DAT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
NTUSER.DAT\Software\Microsoft\Windows\Shell\BagMRU
NTUSER.DAT\Software\Microsoft\Windows\Shell\Bags
NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePIDlMRU
NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedPidlMRU
NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Explorer\TypedPaths
NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Explorer\WordWheelQuery
NTUSER.DAT\Software\Microsoft\Windows\Currentversion\Explorer\UserAssist\{GUID}\Count
SYSTEM\CurrentControlSet\Control\Session Manager\AppCompatCache
AppCompatCacheParser.exe --csv <path to save output> -f <path to SYSTEM hive for data parsing> -c <control set to parse>
C:\Windows\appcompat\Programs\Amcache.hve
Amcache.hve\Root\File\{Volume GUID}\
SYSTEM\CurrentControlSet\Services\bam\UserSettings\{SID}
SYSTEM\CurrentControlSet\Services\dam\UserSettings\{SID}
SYSTEM\CurrentControlSet\Enum\USBTOR
, SYSTEM\CurrentControlSet\Enum\USB
SOFTWARE\Microsoft\Windows Portable Devices\Devices
SYSTEM\CurrentControlSet\Enum\USBSTOR\Ven_Prod_Version\USBSerial#\Properties\{83da6326-97a6-4088-9453-a19231573b29}\0064
SYSTEM\CurrentControlSet\Enum\USBSTOR\Ven_Prod_Version\USBSerial#\Properties\{83da6326-97a6-4088-9453-a19231573b29}\0066
SYSTEM\CurrentControlSet\Enum\USBSTOR\Ven_Prod_Version\USBSerial#\Properties\{83da6326-97a6-4088-9453-a19231573b29}\0067