Skip to main content

Crate winreg_artifacts

Crate winreg_artifacts 

Source
Expand description

Forensic artifact decoders for Windows Registry.

Modules§

amcache
Amcache registry artifact extractor.
catalog_scan
Catalog-driven registry artifact scanner.
com_hijacking
COM object hijacking detection from offline registry hives.
lsadump
LSA dump artifact decoder (lsadump).
lxss
WSL distro registration parser — HKCU\Software\Microsoft\Windows\CurrentVersion\Lxss
path_expansion
Unified registry path-expansion engine.
registry_keys
Generic registry key/value walker — foundation module for forensic artifact extraction.
run_keys
Windows autostart (Run/RunOnce) registry key artifact extractor.
sam
Windows SAM hive artifact extractor.
shellbags
ShellBags registry artifact extractor.
shimcache
ShimCache (AppCompatCache) registry artifact extractor.
svc_diff
Windows service anomaly detector (svc_diff).
typed_urls
Internet Explorer / Edge TypedURLs registry artifact extractor.
userassist
UserAssist registry artifact extractor.