Several hundred unrelated artifacts share one container. This is what is written in them, organised by what an examiner is trying to find out, with the encodings that need dissecting and the conclusions that do not follow.
Where these figures come from. Every value, count and byte map on this page was measured from a live Windows 11 system - the reference system - with its hives captured through a Volume Shadow Copy. Names, paths and hashes are replaced by placeholders of the same length; every offset, size and count is real.
People say "check the registry" the way they say "check the disk". It is not a thing to check; it is a place several hundred unrelated artifacts happen to live, written by different parts of Windows, for different reasons, with different lifetimes and no shared convention about anything.
This page is about what is written in there and what it means. The registry internals guide covers the container: how a hive file is laid out, how a key and a value are stored, what a transaction log is, and how deleted keys are recovered. Everything below assumes that and moves on to the evidence.
The organising idea here is the question, not the key. An examiner does not wake up wanting
to read HKLM\SYSTEM\CurrentControlSet\Services; they want to know what ran,
what persists, what was plugged in, where somebody went. The keys follow from that.
The maps that follow are interactive. Click any byte, or any row of the table beside it, to read the field that byte belongs to and what it decodes to; the tabs above each map switch between the structures, and the map redraws for whichever one is selected.
The first tab is the container itself. A hive is a file in a format of its own, and it announces that in its first four bytes: regf. Everything a hive holds - keys, values, security descriptors, the free space a deleted key is carved back out of - sits after a 4096-byte header called the base block, which says which version the format is, where the root key begins, how much of the file is in use, and whether the file was closed cleanly or was still being written when it was captured. SYSTEM, SOFTWARE, NTUSER.DAT and Amcache.hve are all the same format; only their contents differ.
The other six tabs are those contents, and they share the container and nothing else. A UserAssist counter, a BAM timestamp, a scheduled task's run history, an MRU (most-recently-used) ordering, a disk signature and a device property are six unrelated structures that happen to be stored in the same place. That is the single most important thing to understand about registry forensics, and it is why there is no such thing as a registry parser - only a parser for each thing in it.
Structure is real and measured. Names, paths and hashes are replaced
with a placeholder of the same length, so every offset still adds up
and nothing here identifies the machine it came from. The base block
is read from %SystemRoot%\System32\config\DRIVERS - a
real hive file rather than an NtSaveKeyEx export, because
an export is written fresh and its sequence numbers agree for that
reason rather than because the hive was closed cleanly.
The same fields as a table. Both are drawn from one definition, so the map and the table cannot disagree with each other.
Table 1| Offset | Size | Field | What it is |
|---|
Four artifacts answer this, badly on their own and well together. None is a log; all four are side effects of features that exist for other reasons.
Table 2| Artifact | Written by | Records | Blind to |
|---|---|---|---|
| UserAssist | Explorer | run count, focus time, last run, per user | anything not launched through the shell |
| BAM / DAM | kernel activity moderators | last execution time per binary, per SID | history: it keeps one time, not a series |
| MUICache | Explorer | friendly names of binaries the shell displayed | timing entirely: there is no timestamp |
| AppCompatCache | compatibility engine | path and file mtime, in examined order | whether the file ran at all |
Under Explorer\UserAssist sit 9 GUID subkeys, each with a
Count key whose value names are program paths encoded with ROT13.
Not encrypted - rotated thirteen places, the cipher that ships as a party trick.
It matters for one practical reason: a raw keyword search of a hive for a program
name will not find its UserAssist entry. An examiner grepping an image for
evil.exe gets nothing from this key while the evidence sits right there under a
name that reads as nonsense. On the reference system a sample entry is 15 characters encoded,
and its record is 1,612 bytes.
The record carries a run count and a focus duration in milliseconds. On Windows 7 and later the count is used directly; on XP it was offset by five, so early tooling subtracted five and later tooling did not, and both are still in circulation. A run count of 1 that should read 6, or 6 that should read 1, changes what a report says.
The Background Activity Moderator throttles what background programs may do, and to do that
it keeps the last execution time of each binary, per user SID, under
Services\bam\State\UserSettings. The reference system has 8 SIDs there and
each value is a 24-byte record whose first eight bytes are a FILETIME.
It is the closest thing the registry has to an execution log, and its weakness is that it keeps one timestamp per binary. A program run a hundred times leaves the same single record as one run once. It is also cleared on a schedule, so it is a recent window rather than a history.
The full list, so the page can answer "is this key covered?" rather than leaving it open. A key shown as {ControlSet} is read as CurrentControlSet on a live machine and as the control set Select names in an offline hive.
| Key | Hive | What it is for |
|---|---|---|
Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache | SOFTWARE | Friendly names Explorer cached for executables it has displayed. A path here means the binary existed and was shown, not that it ran. |
Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store | NTUSER.DAT | The Program Compatibility Assistant store: full paths of programs this user started, kept after the file itself is deleted. One key write time covers every entry. Explained in full: Compatibility Assistant |
Microsoft\Windows NT\CurrentVersion\EMDMgmt | SOFTWARE | ReadyBoost's record of volumes it has evaluated, which incidentally names removable drives and their labels. |
Microsoft\Windows NT\CurrentVersion\Image File Execution Options | SOFTWARE | Per-executable debugger settings. A Debugger value here silently substitutes one program for another, which is both a debugging feature and a well-worn persistence and bypass technique. |
Microsoft\Windows\CurrentVersion\Explorer\FeatureUsage | SOFTWARE | Per-application counters Explorer keeps for taskbar and Start usage - how often a window was focused or a button clicked. |
Microsoft\Windows\CurrentVersion\Explorer\UserAssist | SOFTWARE | Per-user counters for programs launched from Explorer, keyed by a ROT13 path. Shell launches only - nothing started from a console appears. |
Microsoft\Windows\CurrentVersion\Search\RecentApps | SOFTWARE | Applications Search has seen used recently, with a launch count. |
Microsoft\Windows\ShellNoRoam\MUICache | SOFTWARE | The pre-Windows-7 location of the same cache. |
{ControlSet}\Control\Session Manager\AppCompatCache | SYSTEM | ShimCache. One value holding a serialised database of every binary the compatibility engine examined. Not proof of execution, and written at shutdown. Explained in full: ShimCache |
{ControlSet}\Control\Session Manager\Memory Management\PrefetchParameters | SYSTEM | Whether Prefetch is enabled. Zero here explains an empty Prefetch directory that would otherwise look like anti-forensics. Explained in full: Prefetch |
{ControlSet}\Services\bam\State\UserSettings | SYSTEM | BAM: the last time each program ran, per account SID, written by the kernel's Background Activity Moderator on Windows 10 1709 and later. Explained in full: BAM |
{ControlSet}\Services\dam\UserSettings | SYSTEM | DAM: the Desktop Activity Moderator's per-SID last-run times, populated on Modern Standby devices and empty on most desktops. Explained in full: DAM |
Persistence is the registry's specialty, and it is much larger than the two keys everyone knows. Crow-Eye reads twenty-eight autostart extensibility points beyond Run and RunOnce: Winlogon's Shell and Userinit, Image File Execution Options, AppInit and AppCert DLLs, Active Setup, LSA packages, Boot Execute, per-user CLSID shadowing, Command Processor AutoRun, Drivers32, shell service objects, Browser Helper Objects, SharedTaskScheduler, shell icon overlays, credential providers, netsh helper DLLs, AMSI providers, security providers, print monitors and processors, network providers, WMI autorecover MOFs, and the per-user Load and Run values.
A Run key entry says a program is configured to start. It does not say it ever has. The two get reported as one thing constantly, and the difference is the difference between "an attacker installed this" and "this attacker's code ran on this date". Answer it with BAM, Prefetch or an event log, not with the Run key.
Crow-Eye names these tables for the artifact, never for the technique that abuses them:
shell_open_command, not "uac_bypass"; clsid_inprocserver32, not "com
hijack". A verdict in a table name becomes a verdict on screen, and the analyst stops being
the one who judges.
The full list, so the page can answer "is this key covered?" rather than leaving it open. A key shown as {ControlSet} is read as CurrentControlSet on a live machine and as the control set Select names in an offline hive.
| Key | Hive | What it is for |
|---|---|---|
Classes | SOFTWARE | File associations and COM registration - what opens what. |
Classes\CLSID | SOFTWARE | The COM class registry. The target of a hijack is usually a CLSID whose server has been pointed somewhere new. |
Classes\CLSID\{clsid}\InprocServer32 | SOFTWARE | The DLL a COM class loads. Ask for the DEFAULT value by name: ThreadingModel usually enumerates first and is not a path. |
Classes\Wow6432Node\CLSID | SOFTWARE | The 32-bit COM classes. On disk this is Classes\Wow6432Node\CLSID - the WOW6432Node\Classes form is a live-only redirection alias that no hive file contains. |
Microsoft\AMSI\Providers | SOFTWARE | Antimalware Scan Interface providers. A provider removed here blinds script scanning. |
Microsoft\Active Setup\Installed Components | SOFTWARE | Runs once per user at first logon. Persistence that waits for a user who has not logged in yet. |
Microsoft\Command Processor | SOFTWARE | AutoRun - a command executed every time cmd.exe starts. |
Microsoft\Netsh | SOFTWARE | Netsh helper DLLs, loaded whenever netsh runs. |
Microsoft\WBEM\CIMOM | SOFTWARE | WMI settings, including the autorecover MOF list - a persistence location that survives a WMI repository rebuild. |
Microsoft\Windows NT\CurrentVersion\Drivers32 | SOFTWARE | Multimedia driver DLLs loaded by the system, and an old autostart. |
Microsoft\Windows NT\CurrentVersion\Print\Printers | SOFTWARE | Installed printers and their drivers. |
Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache | SOFTWARE | Scheduled tasks as the scheduler sees them, including the run history a task's XML file does not carry. |
Microsoft\Windows NT\CurrentVersion\Windows | SOFTWARE | AppInit_DLLs and LoadAppInit_DLLs - a DLL injected into most processes. |
Microsoft\Windows NT\CurrentVersion\Winlogon | SOFTWARE | Userinit, Shell and Notify. Anything appended here runs at logon with the user's rights and is a long-standing hijack point. |
Microsoft\Windows Script Host\Settings | SOFTWARE | Whether Windows Script Host is enabled, which decides if a .vbs or .js payload can run at all. |
Microsoft\Windows\CurrentVersion\App Paths | SOFTWARE | How a bare command name resolves to an executable. Change an entry and typing the name runs something else, with no path to give it away. |
Microsoft\Windows\CurrentVersion\Authentication | SOFTWARE | Credential providers, which load into the logon UI. |
Microsoft\Windows\CurrentVersion\Authentication\Credential Provider Filters | SOFTWARE | Filters that hide or allow credential providers on the logon screen. A filter DLL loads into LogonUI like a provider does. |
Microsoft\Windows\CurrentVersion\Authentication\Credential Providers | SOFTWARE | Credential provider CLSIDs. Each backing DLL loads into LogonUI and sees what is typed at the logon screen, so an unfamiliar one is a credential-theft lead. |
Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects | SOFTWARE | Browser Helper Objects: COM DLLs Internet Explorer and Explorer load at start. Resolved through the CLSID to the DLL on disk. |
Microsoft\Windows\CurrentVersion\Explorer\FileExts | SOFTWARE | Per-extension handler choices. Change the handler for a common file type and opening an ordinary document runs something else. |
Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler | SOFTWARE | Another Explorer-loaded COM list, and another autostart. |
Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers | SOFTWARE | Icon overlay handlers: DLLs Explorer loads into every folder view to draw sync and status badges. Explained in full: shell extensions |
Microsoft\Windows\CurrentVersion\Explorer\StartupApproved | SOFTWARE, per-user | Whether each autostart entry is actually allowed to launch, and when it was switched off. A Run value is a request; this is the answer. Without it every Run value reads as live persistence - on the system behind this page six of ten were disabled, two of them since February. |
Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders | SOFTWARE | Where Windows believes the user's Startup folder is. Repoint it and the Startup folder somebody inspects is not the one that runs. |
Microsoft\Windows\CurrentVersion\Policies\Explorer\Run | SOFTWARE | A policy-backed autostart location, less watched than the ordinary one. |
Microsoft\Windows\CurrentVersion\Run | SOFTWARE, per-user | The classic autostart key. Every value runs at logon. |
Microsoft\Windows\CurrentVersion\RunOnce | SOFTWARE, per-user | Runs once at the next logon and is then deleted, which is why an entry still present is worth reading closely. |
Microsoft\Windows\CurrentVersion\RunServices | SOFTWARE | A legacy autostart location that still executes. |
Microsoft\Windows\CurrentVersion\RunServicesOnce | SOFTWARE | The run-once form of the same legacy location. |
Microsoft\Windows\CurrentVersion\SharedDLLs | SOFTWARE | Reference counts Windows keeps for shared libraries. Mostly inventory, and occasionally the only surviving record that a DLL was ever installed. |
Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad | SOFTWARE | COM objects Explorer loads at startup, by CLSID. |
Policies\Explorer\Run | SOFTWARE | The same policy autostart, reached through the Policies hive path. |
WOW6432Node\Classes\CLSID | SOFTWARE | The redirected 32-bit COM view as the live API presents it. |
WOW6432Node\Microsoft\Active Setup\Installed Components | SOFTWARE | The 32-bit view of Active Setup on a 64-bit machine. |
WOW6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32 | SOFTWARE | The 32-bit view of Drivers32: multimedia driver DLLs a 32-bit process loads through winmm. |
WOW6432Node\Microsoft\Windows NT\CurrentVersion\Windows | SOFTWARE | The 32-bit AppInit location. |
WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects | SOFTWARE | The 32-bit view of Browser Helper Objects, loaded by 32-bit Internet Explorer. |
{ControlSet}\Control\Lsa | SYSTEM | LSA configuration - authentication packages, notification packages, and the four class-name keys that hold the machine's boot key. |
{ControlSet}\Control\Print\Environments | SYSTEM | Print processors and drivers, another spooler-loaded DLL location. |
{ControlSet}\Control\Print\Monitors | SYSTEM | Print monitor DLLs, loaded by the spooler as SYSTEM. |
{ControlSet}\Control\Print\Printers | SYSTEM | The system view of the same printers. |
{ControlSet}\Control\SafeBoot | SYSTEM | Services and drivers that still start in Safe Mode - the boot people use to clean a machine, which is exactly why persistence is placed here. |
{ControlSet}\Control\SecurityProviders | SYSTEM | Security packages loaded by LSA. |
{ControlSet}\Control\SecurityProviders\WDigest | SYSTEM | UseLogonCredential. Set to 1, plaintext credentials return to memory - a single DWORD with a large consequence. |
{ControlSet}\Control\Session Manager | SYSTEM | BootExecute and PendingFileRenameOperations - what runs before Windows starts, and what is moved or deleted at the next boot. |
{ControlSet}\Control\Session Manager\AppCertDlls | SYSTEM | DLLs loaded into every process that calls CreateProcess. Rarely populated legitimately, so anything here is worth explaining. |
{ControlSet}\Control\Windows | SYSTEM | System-wide Windows settings, including error-mode behaviour. |
{ControlSet}\Services | SYSTEM | Every service and driver on the machine. The start type decides whether it runs at boot, and the image path says what runs. |
USB history is spread across several keys that each hold a piece, and the piece most people want - when - is in the least accessible of them.
Table 5| Key | Holds |
|---|---|
| Enum\USB | every USB device by vendor and product, one subkey per physical unit |
| Enum\USBSTOR | mass storage specifically, keyed by serial number |
| MountPoints2 | per user: which volumes that user mounted, which ties a device to a person |
| MountedDevices | drive letter assignments, which ties a device to a letter in other artifacts |
The timestamps live under each device's Properties subkey, in
{83da6326-97a6-4088-9453-a1923f573b29}, as four numbered values:
0064 install, 0065 first install, 0066 last
arrival, 0067 last removal. They are DEVPROP_TYPE_FILETIME, which
is not one of the twelve documented registry types, so a reader that only knows the twelve
refuses them.
Getting these the wrong way round reports the moment a device was unplugged as the moment it was attached. The tell is structural: a device still connected has no 0067 at all, so a "last connected" column that is empty for currently-attached devices has them swapped.
The Properties subkeys are ACL'd such that an elevated administrator reading
through the registry API is refused. Measured on a live machine: an API walk of
Enum\USB reaches 110 keys where reading the same hive as a file reaches 868.
A live tool that does not read the hive file reports no USB timestamps at all, and reports
it as an absence of evidence.
The full list, so the page can answer "is this key covered?" rather than leaving it open. A key shown as {ControlSet} is read as CurrentControlSet on a live machine and as the control set Select names in an offline hive.
| Key | Hive | What it is for |
|---|---|---|
Microsoft\Windows Portable Devices\Devices | SOFTWARE | Friendly names and volume labels for portable devices, which is often the only human-readable name a device left behind. |
Microsoft\Windows Search\VolumeInfoCache | SOFTWARE | Volume labels and serials the search indexer has recorded. |
Microsoft\Windows\CurrentVersion\Explorer\MountPoints2 | SOFTWARE | Volumes this user has mounted, including network shares and removable drives, keyed by volume GUID. |
Microsoft\Windows\CurrentVersion\Explorer\VolumeInfoCache | SOFTWARE | Explorer's own cache of volume labels, including drives long removed. |
MountedDevices | SYSTEM | Drive letters and volume GUIDs mapped to the disk signature and partition offset behind them. This is what ties a physical disk to a machine. |
{ControlSet}\Control\DeviceClasses | SYSTEM | Devices grouped by interface class, with the arrival records that pair with the Enum keys. |
{ControlSet}\Control\FileSystem | SYSTEM | Filesystem behaviour, including whether last-access times are updated - which decides whether an access timestamp means anything at all. |
{ControlSet}\Enum\SCSI | SYSTEM | SCSI-enumerated devices, which is how some external enclosures appear. |
{ControlSet}\Enum\SWD\WPDBUSENUM | SYSTEM | Portable devices - phones and cameras - as the WPD bus enumerates them. |
{ControlSet}\Enum\USB | SYSTEM | Every USB device the machine has enumerated, by vendor and product. |
{ControlSet}\Enum\USBSTOR | SYSTEM | USB mass storage specifically - the key that answers 'what drive was plugged in'. |
{ControlSet}\Enum\USB\{device_id}\{instance_id}\Properties | SYSTEM | The per-device property store holding the connection timestamps. Its ACL denies even an elevated administrator through the API, so these values are readable only from the hive as a file. |
{ControlSet}\Services\BTHPORT\Parameters\Devices | SYSTEM | Bluetooth devices that have been paired, with their addresses and names. |
{ControlSet}\Services\usbstor | SYSTEM | The USB storage driver's start type. Set to 4 it is disabled, which is both a hardening measure and a way to explain missing device history. |
Explorer remembers, and the remembering is per user and per hive. Shellbags get a page of their own; the rest are MRU lists.
All of these — Shellbags, RecentDocs, the dialog MRUs, TypedPaths, RunMRU and the search history, together with what the user ran (UserAssist, BAM, DAM, FeatureUsage, the Compatibility Assistant) and the rest of the user-activity keys — are read together by the Charts button on each of their table tabs, which opens one User Activity dashboard: every source on one timeline, most-visited places, the volumes and shares each pointed at, and per-item detail. Each table is explained one by one below.
An MRU key holds numbered values and one ordering value. In older keys that is
MRUList, a string of letters: on the reference system the RunMRU key holds
2 entries ordered ba. Newer keys use
MRUListEx, four-byte indices terminated by 0xFFFFFFFF.
Reading an MRU key's values in numeric order and reporting that as history is wrong, and it is wrong in a way that looks right: the entries are correct and their order is not. The ordering value is the only thing that says what was used most recently, and a parser that ignores it silently reorders the user's activity.
RecentDocs, OpenSaveMRU, LastVisitedMRU, TypedPaths, WordWheelQuery and the RDP client's history are all this shape. Several store shell items rather than strings, which is the same structure a Shellbag and a shortcut use.
That is where they stop being alike. One holds a shell item list to a file, one holds an application name and then a folder, one holds an application name and a window size with no path in it at all, and two hold nothing but a string - so a row from one supports a sentence a row from another does not. Explained in full: the MRU family
The full list, so the page can answer "is this key covered?" rather than leaving it open. A key shown as {ControlSet} is read as CurrentControlSet on a live machine and as the control set Select names in an offline hive.
| Key | Hive | What it is for |
|---|---|---|
7-Zip\Compression | SOFTWARE | 7-Zip's recent archive and extraction paths. |
Classes\Local Settings\Software\Microsoft\Windows\ShellNoRoam\BagMRU | UsrClass.dat | The pre-Windows-7 Shellbag tree inside UsrClass.dat. Rarely populated on a modern machine, which is exactly why a bag that does land here is worth noticing. All four Shellbag trees |
Classes\Local Settings\Software\Microsoft\Windows\Shell\BagMRU | UsrClass.dat | Shellbags. Every folder opened in Explorer, including folders on drives removed years ago. All four Shellbag trees |
FileZilla Client | SOFTWARE | FileZilla configuration and site history. |
Martin Prikryl\WinSCP 2\Sessions | SOFTWARE | Saved WinSCP sessions, including hostnames and usernames. |
Microsoft\Internet Explorer\TypedURLs | SOFTWARE | URLs typed into the address bar. Still written by parts of Windows long after anyone stopped using the browser. |
Microsoft\Internet Explorer\TypedURLsTime | SOFTWARE | The timestamps for those typed URLs, in a separate key. |
Microsoft\Office | SOFTWARE | Office settings and recent-file lists. |
Microsoft\Terminal Server Client | SOFTWARE | Remote desktop connections this user made, and to which hosts. |
Microsoft\Windows\CurrentVersion\Applets\Regedit | NTUSER.DAT | Registry Editor's LastKey (the key open when it was closed) and its Favorites. Someone browsing the registry by hand leaves this behind. Explained in full: Regedit last key |
Microsoft\Windows\CurrentVersion\CapabilityAccessManager\ConsentStore | SOFTWARE | Which applications hold consent for a capability - microphone, camera, location - and when each last used it. The registry's own record of surveillance-capable access. |
Microsoft\Windows\CurrentVersion\Explorer | SOFTWARE | The Explorer root, parent of most per-user activity keys. |
Microsoft\Windows\CurrentVersion\Explorer\Advanced | NTUSER.DAT | What this user chose to see in Explorer: Hidden, HideFileExt and ShowSuperHidden. ShowSuperHidden=1 is off by default and means protected OS files were made visible. |
Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\CIDSizeMRU | NTUSER.DAT | Programs that opened an Open or Save dialog, newest first, with no path - the executable name only. Explained in full: CIDSizeMRU |
Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedPidlMRU | SOFTWARE | The folder each application last used in a file dialog, which links a program to a location. |
Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU | SOFTWARE | Files chosen in an Open or Save dialog, as shell item lists. |
Microsoft\Windows\CurrentVersion\Explorer\Map Network Drive MRU | SOFTWARE | Network drives the user mapped by hand. |
Microsoft\Windows\CurrentVersion\Explorer\RecentDocs | SOFTWARE | Files opened recently, grouped by extension, ordered by MRUListEx. |
Microsoft\Windows\CurrentVersion\Explorer\RunMRU | SOFTWARE | What was typed into the Run dialog, in use order. |
Microsoft\Windows\CurrentVersion\Explorer\Shell Folders | per-user | Where the shell resolves each known folder to. The resolved half of User Shell Folders, which holds the unexpanded form. |
Microsoft\Windows\CurrentVersion\Explorer\StartPage2 | NTUSER.DAT | ProgramsCache: the Start menu's cached list of program shortcuts, one binary blob of shell items. Explained in full: ProgramsCache |
Microsoft\Windows\CurrentVersion\Explorer\Taskband | per-user | Items pinned to the taskbar, as a shell item list. Deliberate arrangement rather than incidental use. |
Microsoft\Windows\CurrentVersion\Explorer\TypedPaths | SOFTWARE | Paths typed into the Explorer address bar - deliberate navigation, not clicking. |
Microsoft\Windows\CurrentVersion\Explorer\WordWheelQuery | SOFTWARE | Terms typed into Explorer's search box. |
Microsoft\Windows\ShellNoRoam\BagMRU | NTUSER.DAT | The local-only Shellbag tree from the same era. A collection that takes only NTUSER.DAT gets these and misses the modern ones entirely. All four Shellbag trees |
Microsoft\Windows\Shell\BagMRU | NTUSER.DAT | The roaming Shellbag tree, used before Windows 7 moved them to UsrClass.dat. All four Shellbag trees |
RealVNC | SOFTWARE | VNC server configuration, including whether it accepts connections. |
SimonTatham\PuTTY\Sessions | SOFTWARE | Saved PuTTY sessions - hosts, users and ports somebody configured. |
SimonTatham\PuTTY\SshHostKeys | SOFTWARE | SSH host keys PuTTY has accepted, which is a record of hosts actually connected to rather than merely configured. |
Sysinternals | SOFTWARE | EULA-accepted keys for Sysinternals tools. Their presence dates the first run of a tool that is often brought onto a machine deliberately. |
TeamViewer | SOFTWARE | TeamViewer configuration and connection history. |
Trusted Documents\TrustRecords | SECURITY | Office documents the user chose to enable content in - a record of somebody clicking through a macro warning. |
WinRAR\ArcHistory | SOFTWARE | Archives opened in WinRAR. |
WinRAR\DialogEditHistory\ExtrPath | SOFTWARE | Paths archives were extracted to - where the contents of an archive actually landed. |
Each table below is one tab in Crow-Eye, and each has an Anatomy button that opens its own section here. Its Charts button opens the User Activity dashboard, where it shares one timeline with Shellbags, the MRUs and every other source below. The shell-item tables (RecentDocs, the dialog MRUs, TypedPaths, RunMRU, search, MountPoints2) are explained on the Shell Items page.
Programs and shortcuts this user launched through Explorer, with how often and for how long they had focus. The value names are ROT13-encoded paths (why, and what that breaks).
| Field | Detail |
|---|---|
| Key | NTUSER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{GUID}\Count; {CEBFF5CD-...} holds executables, {F4E57C4B-...} shortcuts |
| Value data (Windows 7+) | A 72-byte record: run count at offset 4, focus count at 8, focus time in milliseconds at 12, last execution FILETIME at 60 (byte map above) |
| Names | A path may start with a known-folder GUID instead of a drive ({6D809377-...} is Program Files); UEME_CTL... values are UserAssist's own counters, not programs |
| Timestamp | Per entry: the last execution time |
| Proves | This user launched it through the shell, the count and the last time |
| Does not prove | Execution from a command line or a service, which UserAssist never sees |
| In Crow-Eye | Table UserAssist: decoded path, run count, focus count, focus time, last execution, user |
| On the User Activity dashboard | Source UserAssist, dated by last execution; the counters are left out |
The kernel's record of the last time each program ran, per user SID (how BAM works).
| Field | Detail |
|---|---|
| Key | SYSTEM\{ControlSet}\Services\bam\State\UserSettings\<SID> (Windows 10 1709 and later; earlier builds used Services\bam\UserSettings) |
| Values | Name: a device path (\Device\HarddiskVolume3\...) or a Store app ID. Data: 24 bytes, a FILETIME first. Version and SequenceNumber are bookkeeping, not programs |
| Timestamp | Per entry: the last execution |
| Proves | That binary ran under that SID, most recently at that time - including programs never launched from Explorer |
| Does not prove | Earlier runs: one time per binary, and entries are pruned after a short window |
| In Crow-Eye | Table BAM: process path, app name, SID (resolved to a user), last execution |
| On the User Activity dashboard | Source BAM, dated by last execution |
\Device\HarddiskVolume3 is the third volume the kernel numbered at boot, not C:. Map it through the partition layout before writing a drive letter in a report.
The same record as BAM, kept by the Desktop Activity Moderator. It exists only on devices that support Modern Standby (connected standby), so on most desktops the table is empty - and that is not a gap.
| Field | Detail |
|---|---|
| Key | SYSTEM\{ControlSet}\Services\dam\State\UserSettings\<SID> |
| Values | Same format as BAM: a FILETIME first; some builds also keep an execution count |
| Timestamp | Per entry: the last execution |
| Proves | That binary ran under that SID on a Modern Standby device |
| Does not prove | Anything on a machine without Modern Standby, where Windows never writes it |
| In Crow-Eye | Table DAM |
| On the User Activity dashboard | Source DAM |
Friendly names Explorer read from executables' version resources - which happens when the shell displays or launches them.
| Field | Detail |
|---|---|
| Key | UsrClass.dat\Local Settings\Software\Microsoft\Windows\Shell\MuiCache (Vista and later) |
| Values | Name: <path>.FriendlyAppName or .ApplicationCompany. Data: the text |
| Timestamp | None per entry |
| Proves | The shell handled that executable for this user, usually because it was launched |
| Does not prove | When, or how often |
| In Crow-Eye | Table MUICache: path, application name, company |
| On the User Activity dashboard | Source MUICache, undated: listed under All items |
Windows 10's early record of recently used apps and the files each opened (builds 1507 to 1607; later builds dropped it).
| Field | Detail |
|---|---|
| Key | NTUSER\Software\Microsoft\Windows\CurrentVersion\Search\RecentApps\{GUID}, with RecentItems subkeys |
| Values | AppId, AppPath, LaunchCount, LastAccessedTime (FILETIME) |
| Timestamp | Per app: the last access |
| Proves | The app was used, how often, and when last |
| Does not prove | Anything on builds that never wrote the key |
| In Crow-Eye | Table RecentApps |
| On the User Activity dashboard | Source RecentApps |
Per-program counters kept by the taskbar (Windows 10 1903 and later).
| Field | Detail |
|---|---|
| Key | NTUSER\Software\Microsoft\Windows\CurrentVersion\Explorer\FeatureUsage, subkeys AppSwitched (switched to from the taskbar), AppLaunch (launched from a pin), ShowJumpView (jump list opened), AppBadgeUpdated, TrayButtonClicked |
| Values | Name: a program path or AppUserModelID. Data: a DWORD count |
| Timestamp | Only each subkey's last-write time - one upper bound shared by every counter in it |
| Proves | The user interacted with that program through the taskbar, that many times |
| Does not prove | When any one interaction happened |
| In Crow-Eye | Table FeatureUsage: usage type, program, count, key upper bound |
| On the User Activity dashboard | Source FeatureUsage, undated: plotting every counter on the subkey's day would be a false spike |
Programs the Program Compatibility Assistant watched because the user ran them - installers and downloaded tools especially.
| Field | Detail |
|---|---|
| Key | NTUSER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store |
| Values | Name: the full path of the program. Data: a binary record (Crow-Eye keeps its size) |
| Timestamp | Only the key's last-write time |
| Proves | This user ran that executable - the path survives after the file is deleted |
| Does not prove | When; on Windows 11 22H2 and later PCA also keeps text logs in C:\Windows\appcompat\pca |
| In Crow-Eye | Table CompatibilityAssistant |
| On the User Activity dashboard | Source Compatibility Assistant, undated |
Which programs the user opened each file type with, and which one they chose as the default.
| Field | Detail |
|---|---|
| Key | NTUSER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\<.ext> with OpenWithList (an MRU of programs), OpenWithProgids and UserChoice (the default) |
| Timestamp | Each subkey's last-write time |
| Proves | This user opened that type with that program at least once, or set it as the default |
| Does not prove | Which file |
| In Crow-Eye | Table file_exts: extension, list type, program or ProgID |
| On the User Activity dashboard | Source File associations, undated |
.001 opened with FTK Imager, or .ps1 with Notepad, says what the user did with a file type even when the file itself is gone.
The Start menu's cached list of programs, stored as shell items.
| Field | Detail |
|---|---|
| Key | NTUSER\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage2, value ProgramsCache |
| Values | One binary value: a list of shell items. Crow-Eye records its presence and size, not its decoded entries |
| Timestamp | None per entry |
| Proves | The value exists for this user; decoded, it lists programs the Start menu offered |
| Does not prove | Execution |
| In Crow-Eye | Table programs_cache |
| On the User Activity dashboard | Source ProgramsCache, undated |
Where Registry Editor was looking when it was last closed, and the keys saved as favourites.
| Field | Detail |
|---|---|
| Key | NTUSER\Software\Microsoft\Windows\CurrentVersion\Applets\Regedit: value LastKey, subkey Favorites |
| Timestamp | The key's last-write time, close to when Registry Editor was last closed |
| Proves | Registry Editor was used by this user - a LastKey on a Run key or a service is worth a look |
| Does not prove | What was changed |
| In Crow-Eye | Table regedit_lastkey |
| On the User Activity dashboard | Source Regedit last key |
Addresses typed into the Internet Explorer (and Explorer) address bar.
| Field | Detail |
|---|---|
| Keys | NTUSER\Software\Microsoft\Internet Explorer\TypedURLs (url1 ... url25, url1 newest) and TypedURLsTime (a FILETIME per urlN, Windows 8 and later) |
| Timestamp | Per entry when TypedURLsTime exists; otherwise only the key's write time |
| Proves | The user typed that address |
| Does not prove | Browsing in other browsers - see the browser page |
| In Crow-Eye | Table BrowserHistory (the registry tab of that name) |
| On the User Activity dashboard | Source TypedURLs, dated by TypedURLsTime when present |
Explained in full: browser forensics
Hosts this user connected to with Remote Desktop.
| Field | Detail |
|---|---|
| Keys | NTUSER\Software\Microsoft\Terminal Server Client\Default (MRU0 ... MRU9) and \Servers\<host> with UsernameHint |
| Timestamp | Each key's last-write time |
| Proves | An outbound Remote Desktop connection was attempted to that host, and with which account name |
| Does not prove | That it succeeded - check the target's logon events (4624 type 10) |
| In Crow-Eye | Table RDPClientMRU |
| On the User Activity dashboard | Source RDPClientMRU; every row counts as network activity |
Documents opened in Word, Excel and PowerPoint, and the documents the user let run active content.
| Field | Detail |
|---|---|
| Keys | NTUSER\Software\Microsoft\Office\<version>\<app>\File MRU and Place MRU (Microsoft 365 adds User MRU\<id>\...); ...\Security\Trusted Documents\TrustRecords |
| Values | MRU items look like [F00000000][T01D...][O00000000]*C:\path; the T field is a FILETIME in hex - the last open. TrustRecords: value name = document path |
| Timestamp | Per MRU entry (the T field); TrustRecords carry a FILETIME in their data |
| Proves | The document was opened in Office; a trust record means the user clicked Enable Editing or Enable Content (a trailing FF FF FF 7F is widely documented as macros enabled) |
| Does not prove | What the document contained |
| In Crow-Eye | Table OfficeDocuments (TrustRecords included) |
| On the User Activity dashboard | Source Office MRU |
What third-party tools remember, read from their own keys.
| Field | Detail |
|---|---|
| PuTTY | Software\SimonTatham\PuTTY\Sessions (saved sessions) and SshHostKeys (every SSH host this user accepted a key for) |
| WinSCP | Software\Martin Prikryl\WinSCP 2\Sessions: saved file-transfer sessions |
| WinRAR | Software\WinRAR\ArcHistory (archives opened) and DialogEditHistory\ExtrPath (extraction folders) |
| 7-Zip | Software\7-Zip\Compression: archive history |
| Sysinternals | Software\Sysinternals\<tool> EulaAccepted: the tool ran at least once for this user |
| TeamViewer, FileZilla, RealVNC | Configuration keys - presence means the tool was installed or used by this user |
| Timestamp | Each key's last-write time |
| Proves | Remote access, file transfer or archiving tools were used, and where they pointed |
| In Crow-Eye | Table ApplicationArtifacts |
| On the User Activity dashboard | Source App MRUs |
When each app last used the camera, microphone or location, with a start and a stop time (Windows 10 1903 and later).
| Field | Detail |
|---|---|
| Keys | SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\ConsentStore\<capability> and the same path in NTUSER; Store apps by package name, desktop programs under NonPackaged with # in place of \ |
| Values | LastUsedTimeStart, LastUsedTimeStop (FILETIMEs), Value (Allow / Deny) |
| Timestamp | Per app: the start and stop of its last use |
| Proves | That program had the camera, microphone or location in use between those two times |
| Does not prove | What was recorded, or earlier uses |
| In Crow-Eye | Table app_permissions: capability, app, permission, last used start and stop |
| On the User Activity dashboard | Source Camera / mic / location, dated by last-use start |
Identity and network answer the questions that come up when an image arrives with no context: whose machine is this, what was it called, what network was it on, when was it installed.
Table 8| Key | Answers |
|---|---|
| ComputerName | the machine name, and note there are two: the active one and the one pending a reboot |
| MachineGuid | a stable identifier that survives renames |
| NetworkList\Profiles | every network joined, with first and last connection, and the gateway's MAC |
| ProfileList | SID to profile path, which is how any per-user artifact gets a name attached |
| TimeZoneInformation | the offset every local timestamp on the machine was written in |
Each network profile records the default gateway's MAC address. That identifies a specific piece of hardware, so a laptop's profile list is a record of which physical networks it was carried to and when it first and last saw each. It is one of the few registry artifacts that speaks to location.
The registry stores SIDs, not names. Resolving them with the API on the examiner's workstation returns that workstation's accounts, and a local SID that happens to collide gets a confident wrong name attached. The mapping has to come from the image's own SAM and ProfileList.
The full list, so the page can answer "is this key covered?" rather than leaving it open. A key shown as {ControlSet} is read as CurrentControlSet on a live machine and as the control set Select names in an offline hive.
| Key | Hive | What it is for |
|---|---|---|
Microsoft\Cryptography | SOFTWARE | MachineGuid, which identifies this installation across rebuilds of almost everything else. |
Microsoft\Windows Defender\Exclusions | SOFTWARE | Paths, extensions and processes Defender ignores. An exclusion added by an intruder is a quiet way to make a payload invisible. |
Microsoft\Windows NT\CurrentVersion | SOFTWARE | The Windows build, edition, install date and registered owner. |
Microsoft\Windows NT\CurrentVersion\NetworkCards | SOFTWARE | The adapter inventory by installation index. Names cards that no longer have an interface, which is how a removed adapter leaves a trace. |
Microsoft\Windows NT\CurrentVersion\NetworkList\Profiles | SOFTWARE | Networks the evidence machine has joined, with first and last connection times. |
Microsoft\Windows NT\CurrentVersion\NetworkList\Signatures\Managed | SOFTWARE | Domain networks, identified by their gateway MAC - which places a machine on a physical network rather than merely naming one. |
Microsoft\Windows NT\CurrentVersion\NetworkList\Signatures\Unmanaged | SOFTWARE | The same signatures for non-domain networks - home and public Wi-Fi. |
Microsoft\Windows NT\CurrentVersion\ProfileList | SOFTWARE | Every user profile by SID, with its path. This is what turns a SID in another artifact into a person. |
Microsoft\Windows NT\CurrentVersion\SystemRestore | SOFTWARE | Whether restore points are being created, and therefore whether earlier hive copies exist to compare against. |
Microsoft\Windows Search\Gather | SOFTWARE | What the search indexer is scoped to crawl, and therefore which files could appear in its database at all. |
Microsoft\Windows\CurrentVersion | SOFTWARE | Per-user Windows settings, parent of the Run and Explorer keys. |
Microsoft\Windows\CurrentVersion\Group Policy\History | SOFTWARE | Group policy objects that have been applied, and when - which says what domain the evidence machine answered to. |
Microsoft\Windows\CurrentVersion\Internet Settings | SOFTWARE | Proxy configuration, which decides where a machine's traffic went. |
Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap | per-user | Hosts, protocols and ranges assigned to a security zone. A host moved into Trusted Sites runs content every other zone would block. |
Microsoft\Windows\CurrentVersion\Policies\Attachments | per-user | Attachment handling, including SaveZoneInformation. Suppressed, downloaded files lose their Mark of the Web and stop warning anyone. |
Microsoft\Windows\CurrentVersion\Policies\System | SOFTWARE | UAC configuration, including the consent prompt behaviour that a bypass depends on. |
Microsoft\Windows\CurrentVersion\Uninstall | SOFTWARE | Installed software, with publisher, version and install date. |
Microsoft\Windows\CurrentVersion\WINEVT\Channels | SOFTWARE | Every event log channel, whether it is enabled and where its file lives. A disabled channel explains a silence that would otherwise look like nothing happened. |
Microsoft\Windows\CurrentVersion\WindowsUpdate | SOFTWARE | Update client state, including when it last checked and installed. |
Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update | SOFTWARE | Automatic update policy - whether patches were being applied at all. |
Policies\Microsoft\Windows Defender | SOFTWARE | Defender policy, including whether it has been disabled outright. |
Policies\Microsoft\Windows Defender\Exclusions | SOFTWARE | The policy-enforced form of the same exclusions. |
Policies\Microsoft\Windows Defender\Real-Time Protection | SOFTWARE | Real-time protection settings - the switch that turns off live scanning. |
Policies\Microsoft\Windows\PowerShell\ModuleLogging | SOFTWARE | Whether PowerShell module activity is logged. |
Policies\Microsoft\Windows\PowerShell\ScriptBlockLogging | SOFTWARE | Whether PowerShell records the script blocks it executes. Off, a whole class of evidence was never created. |
Select | SYSTEM | Which ControlSet is current. An offline hive has no CurrentControlSet, so this value is what resolves it. |
Setup | SYSTEM | Setup and upgrade history, which dates the build the machine came from. |
WOW6432Node\Microsoft\Windows | SOFTWARE | The 32-bit view of per-user Windows settings. |
WOW6432Node\Microsoft\Windows NT | SOFTWARE | The 32-bit view of the system settings tree. |
WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall | SOFTWARE | The 32-bit software inventory on a 64-bit machine. |
{ControlSet}\Control\BackupRestore\FilesNotToSnapshot | SYSTEM | Files excluded from shadow copies. An addition here removes something from every future snapshot. |
{ControlSet}\Control\ComputerName\ActiveComputerName | SYSTEM | The name in force now. The two differ after a rename that has not rebooted, and the difference is itself a finding. |
{ControlSet}\Control\ComputerName\ComputerName | SYSTEM | The machine name as it will be after the next reboot. |
{ControlSet}\Control\CrashControl | SYSTEM | Crash dump settings, and whether a dump would exist to collect. |
{ControlSet}\Control\DeviceGuard | SYSTEM | Virtualisation-based security and Credential Guard. Whether LSASS was protected decides whether credential theft was even possible. |
{ControlSet}\Control\Network | SYSTEM | Network adapters and their bindings. |
{ControlSet}\Control\Network\{4d36e972-e325-11ce-bfc1-08002be10318} | SYSTEM | The network adapter class: each adapter GUID with the connection name shown in ncpa.cpl, so a Tcpip interface GUID elsewhere in the case can be named. |
{ControlSet}\Control\NetworkProvider\Order | SYSTEM | The order network providers are consulted in. |
{ControlSet}\Control\Nls\Language | SYSTEM | The system locale and the language Windows was installed in - an attribution signal that survives almost everything else. |
{ControlSet}\Control\ProductOptions | SYSTEM | Product type - whether this is a workstation, a server or a domain controller. |
{ControlSet}\Control\Session Manager\Environment | SYSTEM | System-wide environment variables, including PATH - which decides which binary a bare command resolves to. |
{ControlSet}\Control\Session Manager\Memory Management | SYSTEM | Paging behaviour, including whether the page file is cleared at shutdown. |
{ControlSet}\Control\Session Manager\Power | SYSTEM | Power and fast startup. HiberbootEnabled decides whether a shutdown was a real one, and therefore whether ShimCache was flushed at all. |
{ControlSet}\Control\Terminal Server | SYSTEM | Whether remote desktop is enabled at all. |
{ControlSet}\Control\Terminal Server\WinStations\RDP-Tcp | SYSTEM | The RDP listener - its port, and whether network level authentication is required. |
{ControlSet}\Control\TimeZoneInformation | SYSTEM | The machine's timezone and bias. Needed to read every local timestamp the evidence contains, including the DOS times inside shell items. |
{ControlSet}\Control\hivelist | SYSTEM | Where every loaded hive lives on disk - the map an image parser uses to find the files it has not been handed. |
{ControlSet}\Services\Dnscache\Parameters | SYSTEM | DNS client settings, including whether the resolver cache is running - which decides whether a lookup left any local trace to find. |
{ControlSet}\Services\EventLog | SYSTEM | Event log service configuration and per-log retention. |
{ControlSet}\Services\LanmanServer\Shares | SYSTEM | Shares the evidence machine offers, and the paths behind them. |
{ControlSet}\Services\SharedAccess\Parameters | SYSTEM | Firewall rules and internet connection sharing configuration. |
{ControlSet}\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | SYSTEM | Every Windows Firewall rule as a pipe-delimited string: direction, action, program, ports. A rule allowing inbound traffic to an unusual program is a lead. |
{ControlSet}\Services\Tcpip\Parameters\Interfaces | SYSTEM | Per-interface IP configuration, including DHCP leases and the server that issued them. |
The five questions above each carry their own warning where it belongs, in the artifact it applies to. Four limits are not about any one key — they are properties of the registry itself, and they apply to every finding on this page.
The registry timestamps keys. It does not timestamp values. A key holding forty values has one last-write time, and any one of those forty writes could have set it — as could a write that only changed a value already present, or a subkey being created. So a key time is an upper bound on everything beneath it, shared by all of it. Reporting "this value was written at 14:02" is a claim the registry cannot support unless the key holds exactly one value.
This is the error the whole of Question 2 is written against, and it generalises. A Run key entry, a service, a scheduled-task registration and a COM registration all say the same thing: the machine was told to do something. None of them says it happened. The proof of execution is somewhere else — Prefetch, an event log, an AmCache entry with a real run time beside it.
Windows does not write every change straight into the hive file. Changes land in the
transaction logs (.LOG1, .LOG2) and are merged later, so a hive
file copied from a running machine can be missing the most recent writes — including
the ones an intruder made minutes ago. Reading the live registry through the API sees the
merged view; copying the file may not. When the two disagree, the logs are the difference,
and they are part of the evidence rather than a nuisance.
A deleted key or value is unlinked, not erased: its cell is marked free and its contents survive until that space is reused, which is why a recovered value can be read long after it was removed. The same property runs the other way. A key that exists may be a leftover from software uninstalled years ago, written once and never touched since — the registry keeps what nobody cleaned up, and says nothing about whether it still matters.
What it is genuinely good for: answering which question. No other artifact on a Windows machine spans execution, persistence, device history, user navigation and machine identity in one container, with the same acquisition and the same parser. The five questions above are the shape of that strength: the registry is rarely the only evidence for a finding, and it is very often the first place the finding is visible.
Seventy-odd tables, one per artifact, named for what they hold. Both acquisition routes - the live registry through the API, and the hive files through a shadow copy, raw disk or a backup-privileged export - produce the same tables, so a case has the same shape either way. Where an artifact needs a decoder rather than a read, that decoder is shared: the same code reads a shell item whether it came from a Shellbag, a Jump List or a shortcut. Explained in full: Jump Lists
Deleted keys and values are carved from the hive's freed cells and marked
(deleted) in a column of their own, with the key path reconstructed where the
parent chain survives and left empty where it does not. And every hive's transaction logs are
replayed before parsing, because a hive read from a running machine is mid-transaction by
default and its most recent changes are in the log rather than the file.
The registry internals guide is the companion to this page: it explains the file this evidence sits in, and why several of the behaviours above are structural rather than optional.
Each row below records a change that alters what a reader may conclude, not only how the bytes are arranged. A parser written against one Windows release returns nothing against another, and does so without raising an error.
Table 10| Windows | What changed | What it means for a reader |
|---|---|---|
| 3.1 | REG.DAT - one file, file associations only | The registry begins as a replacement for WIN.INI. |
| 95 and NT | The hive format this page describes, split into several files | SYSTEM, SOFTWARE, NTUSER.DAT. The container has not fundamentally changed since. |
| Vista | Transaction logs become mandatory; UsrClass.dat takes over Shellbags | A hive on disk may be missing its most recent changes until the logs are replayed. |
| 8 | BAM and DAM arrive | The kernel starts keeping its own per-executable timestamps, which is the most reliable execution artifact in the registry. |
| 10 and 11 | AppCompatCache loses its execution flag; AmCache moves to the Inventory* schema | Two of the three registry execution artifacts change meaning. The literature mostly did not. |
| Type | Name | What it holds |
|---|---|---|
1 | REG_SZ | A string. Most of the registry. |
3 | REG_BINARY | Bytes with no declared meaning - every map above is one of these. |
4 | REG_DWORD | 32-bit integer, usually stored inline in the record. |
7 | REG_MULTI_SZ | Null-separated strings, double null at the end. |
11 | REG_QWORD | 64-bit integer. |
0xFFFF0010 | DEVPROP_TYPE_FILETIME | Not one of the twelve. Eight bytes, and it is where USB connection times live. |
0xFFFF0012 | DEVPROP_TYPE_STRING | UTF-16 text under a device key. |
0xFFFF000D | DEVPROP_TYPE_GUID | Sixteen bytes. |
| Question | Key | Caveat |
|---|---|---|
| What ran, from the shell | UserAssist | Explorer launches only. Nothing from a console or a service. |
| What ran, per the kernel | bam\State\UserSettings | Roughly one week of history, then cleared. |
| What was examined | AppCompatCache | Not execution. Written at shutdown. |
| What is installed | AmCache Inventory* | Presence, not execution. Explained in full: AmCache |
| What persists | Run, RunOnce, services, TaskCache | Persistence is not execution - it says what is scheduled, not what happened. |
| What was plugged in | Enum\USBSTOR, MountedDevices | Connection times live in Properties, which denies even an elevated administrator through the API. |
| Where the user went | Shellbags, RecentDocs, MRU keys | MRUListEx is the only thing recording order. |
The preceding sections describe what intact keys support. This section describes the registry after an attempt to remove or evade it, which is the condition in which it is frequently encountered. In most rows the attempt leaves a trace of its own.
Table 13| Technique | What is done | What survives |
|---|---|---|
| Deleting a key | The key is unlinked from its parent. | The cell is freed, not erased. Name, timestamp and values usually survive until something allocates over them - which is what carving recovers. |
| Clearing UserAssist | The Count subkeys are emptied. | An account with a login history and an empty UserAssist is an anomaly. BAM and Prefetch are unaffected and answer the same question. |
| Renaming rather than deleting | A persistence value is renamed to look legitimate. | The key's last-written timestamp still moves. A Run key whose write time is far from the software's install date is worth explaining. |
| Loosening permissions | A persistence key's ACL is changed so a non-administrator can write it. | The key stops sharing its siblings' security descriptor and gets its own. Visible structurally without reading a single ACL - see the internals guide. |
| Operating in a live-only window | Everything is done in volatile keys. | Volatile keys are never written to a file, so an offline image cannot contain them. This is one of the few things a live parse sees and an image genuinely does not. |