Eye Describe Anatomy

Registry forensics: structure, contents and evidential limits

Several hundred unrelated artifacts share one container. This is what is written in them, organised by what an examiner is trying to find out, with the encodings that need dissecting and the conclusions that do not follow.

What this page covers

  1. The registry is not one artifact
  2. One container, and the six unrelated things inside it
  3. Question 1: what ran on this machine?
  4. Question 2: what will run again?
  5. Question 3: what was plugged into it?
  6. Question 4: where did the user go?
  7. Every user-activity table, one by one
  8. Question 5: what was this machine, and what was it connected to?
  9. What the registry supports, and what it does not
  10. What Crow-Eye does with all of this
  11. How the registry's artifacts changed across Windows
  12. Reference
  13. Anti-forensic handling, and what survives it

Where these figures come from. Every value, count and byte map on this page was measured from a live Windows 11 system - the reference system - with its hives captured through a Volume Shadow Copy. Names, paths and hashes are replaced by placeholders of the same length; every offset, size and count is real.

The registry is not one artifact

People say "check the registry" the way they say "check the disk". It is not a thing to check; it is a place several hundred unrelated artifacts happen to live, written by different parts of Windows, for different reasons, with different lifetimes and no shared convention about anything.

This page is about what is written in there and what it means. The registry internals guide covers the container: how a hive file is laid out, how a key and a value are stored, what a transaction log is, and how deleted keys are recovered. Everything below assumes that and moves on to the evidence.

The organising idea here is the question, not the key. An examiner does not wake up wanting to read HKLM\SYSTEM\CurrentControlSet\Services; they want to know what ran, what persists, what was plugged in, where somebody went. The keys follow from that.

The maps that follow are interactive. Click any byte, or any row of the table beside it, to read the field that byte belongs to and what it decodes to; the tabs above each map switch between the structures, and the map redraws for whichever one is selected.

One container, and the six unrelated things inside it

The first tab is the container itself. A hive is a file in a format of its own, and it announces that in its first four bytes: regf. Everything a hive holds - keys, values, security descriptors, the free space a deleted key is carved back out of - sits after a 4096-byte header called the base block, which says which version the format is, where the root key begins, how much of the file is in use, and whether the file was closed cleanly or was still being written when it was captured. SYSTEM, SOFTWARE, NTUSER.DAT and Amcache.hve are all the same format; only their contents differ.

The other six tabs are those contents, and they share the container and nothing else. A UserAssist counter, a BAM timestamp, a scheduled task's run history, an MRU (most-recently-used) ordering, a disk signature and a device property are six unrelated structures that happen to be stored in the same place. That is the single most important thing to understand about registry forensics, and it is why there is no such thing as a registry parser - only a parser for each thing in it.

Structure is real and measured. Names, paths and hashes are replaced with a placeholder of the same length, so every offset still adds up and nothing here identifies the machine it came from. The base block is read from %SystemRoot%\System32\config\DRIVERS - a real hive file rather than an NtSaveKeyEx export, because an export is written fresh and its sequence numbers agree for that reason rather than because the hive was closed cleanly.

Figure 1
Live Byte Selection

Full dissection reference

The same fields as a table. Both are drawn from one definition, so the map and the table cannot disagree with each other.

Table 1
OffsetSizeFieldWhat it is

Question 1: what ran on this machine?

Four artifacts answer this, badly on their own and well together. None is a log; all four are side effects of features that exist for other reasons.

Table 2
ArtifactWritten byRecordsBlind to
UserAssistExplorerrun count, focus time, last run, per useranything not launched through the shell
BAM / DAMkernel activity moderatorslast execution time per binary, per SIDhistory: it keeps one time, not a series
MUICacheExplorerfriendly names of binaries the shell displayedtiming entirely: there is no timestamp
AppCompatCachecompatibility enginepath and file mtime, in examined orderwhether the file ran at all

UserAssist, and the ROT13 that fools keyword searches

Under Explorer\UserAssist sit 9 GUID subkeys, each with a Count key whose value names are program paths encoded with ROT13. Not encrypted - rotated thirteen places, the cipher that ships as a party trick.

It matters for one practical reason: a raw keyword search of a hive for a program name will not find its UserAssist entry. An examiner grepping an image for evil.exe gets nothing from this key while the evidence sits right there under a name that reads as nonsense. On the reference system a sample entry is 15 characters encoded, and its record is 1,612 bytes.

The focus time is milliseconds, and the run count does not start at one

The record carries a run count and a focus duration in milliseconds. On Windows 7 and later the count is used directly; on XP it was offset by five, so early tooling subtracted five and later tooling did not, and both are still in circulation. A run count of 1 that should read 6, or 6 that should read 1, changes what a report says.

BAM and DAM: the kernel's own record

The Background Activity Moderator throttles what background programs may do, and to do that it keeps the last execution time of each binary, per user SID, under Services\bam\State\UserSettings. The reference system has 8 SIDs there and each value is a 24-byte record whose first eight bytes are a FILETIME.

It is the closest thing the registry has to an execution log, and its weakness is that it keeps one timestamp per binary. A program run a hundred times leaves the same single record as one run once. It is also cleared on a schedule, so it is a recent window rather than a history.

Every key Crow-Eye reads for this question (12)

The full list, so the page can answer "is this key covered?" rather than leaving it open. A key shown as {ControlSet} is read as CurrentControlSet on a live machine and as the control set Select names in an offline hive.

Table 3
KeyHiveWhat it is for
Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCacheSOFTWAREFriendly names Explorer cached for executables it has displayed. A path here means the binary existed and was shown, not that it ran.
Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\StoreNTUSER.DATThe Program Compatibility Assistant store: full paths of programs this user started, kept after the file itself is deleted. One key write time covers every entry. Explained in full: Compatibility Assistant
Microsoft\Windows NT\CurrentVersion\EMDMgmtSOFTWAREReadyBoost's record of volumes it has evaluated, which incidentally names removable drives and their labels.
Microsoft\Windows NT\CurrentVersion\Image File Execution OptionsSOFTWAREPer-executable debugger settings. A Debugger value here silently substitutes one program for another, which is both a debugging feature and a well-worn persistence and bypass technique.
Microsoft\Windows\CurrentVersion\Explorer\FeatureUsageSOFTWAREPer-application counters Explorer keeps for taskbar and Start usage - how often a window was focused or a button clicked.
Microsoft\Windows\CurrentVersion\Explorer\UserAssistSOFTWAREPer-user counters for programs launched from Explorer, keyed by a ROT13 path. Shell launches only - nothing started from a console appears.
Microsoft\Windows\CurrentVersion\Search\RecentAppsSOFTWAREApplications Search has seen used recently, with a launch count.
Microsoft\Windows\ShellNoRoam\MUICacheSOFTWAREThe pre-Windows-7 location of the same cache.
{ControlSet}\Control\Session Manager\AppCompatCacheSYSTEMShimCache. One value holding a serialised database of every binary the compatibility engine examined. Not proof of execution, and written at shutdown. Explained in full: ShimCache
{ControlSet}\Control\Session Manager\Memory Management\PrefetchParametersSYSTEMWhether Prefetch is enabled. Zero here explains an empty Prefetch directory that would otherwise look like anti-forensics. Explained in full: Prefetch
{ControlSet}\Services\bam\State\UserSettingsSYSTEMBAM: the last time each program ran, per account SID, written by the kernel's Background Activity Moderator on Windows 10 1709 and later. Explained in full: BAM
{ControlSet}\Services\dam\UserSettingsSYSTEMDAM: the Desktop Activity Moderator's per-SID last-run times, populated on Modern Standby devices and empty on most desktops. Explained in full: DAM

Question 2: what will run again?

Persistence is the registry's specialty, and it is much larger than the two keys everyone knows. Crow-Eye reads twenty-eight autostart extensibility points beyond Run and RunOnce: Winlogon's Shell and Userinit, Image File Execution Options, AppInit and AppCert DLLs, Active Setup, LSA packages, Boot Execute, per-user CLSID shadowing, Command Processor AutoRun, Drivers32, shell service objects, Browser Helper Objects, SharedTaskScheduler, shell icon overlays, credential providers, netsh helper DLLs, AMSI providers, security providers, print monitors and processors, network providers, WMI autorecover MOFs, and the per-user Load and Run values.

Persistence is not execution

A Run key entry says a program is configured to start. It does not say it ever has. The two get reported as one thing constantly, and the difference is the difference between "an attacker installed this" and "this attacker's code ran on this date". Answer it with BAM, Prefetch or an event log, not with the Run key.

Crow-Eye names these tables for the artifact, never for the technique that abuses them: shell_open_command, not "uac_bypass"; clsid_inprocserver32, not "com hijack". A verdict in a table name becomes a verdict on screen, and the analyst stops being the one who judges.

Every key Crow-Eye reads for this question (49)

The full list, so the page can answer "is this key covered?" rather than leaving it open. A key shown as {ControlSet} is read as CurrentControlSet on a live machine and as the control set Select names in an offline hive.

Table 4
KeyHiveWhat it is for
ClassesSOFTWAREFile associations and COM registration - what opens what.
Classes\CLSIDSOFTWAREThe COM class registry. The target of a hijack is usually a CLSID whose server has been pointed somewhere new.
Classes\CLSID\{clsid}\InprocServer32SOFTWAREThe DLL a COM class loads. Ask for the DEFAULT value by name: ThreadingModel usually enumerates first and is not a path.
Classes\Wow6432Node\CLSIDSOFTWAREThe 32-bit COM classes. On disk this is Classes\Wow6432Node\CLSID - the WOW6432Node\Classes form is a live-only redirection alias that no hive file contains.
Microsoft\AMSI\ProvidersSOFTWAREAntimalware Scan Interface providers. A provider removed here blinds script scanning.
Microsoft\Active Setup\Installed ComponentsSOFTWARERuns once per user at first logon. Persistence that waits for a user who has not logged in yet.
Microsoft\Command ProcessorSOFTWAREAutoRun - a command executed every time cmd.exe starts.
Microsoft\NetshSOFTWARENetsh helper DLLs, loaded whenever netsh runs.
Microsoft\WBEM\CIMOMSOFTWAREWMI settings, including the autorecover MOF list - a persistence location that survives a WMI repository rebuild.
Microsoft\Windows NT\CurrentVersion\Drivers32SOFTWAREMultimedia driver DLLs loaded by the system, and an old autostart.
Microsoft\Windows NT\CurrentVersion\Print\PrintersSOFTWAREInstalled printers and their drivers.
Microsoft\Windows NT\CurrentVersion\Schedule\TaskCacheSOFTWAREScheduled tasks as the scheduler sees them, including the run history a task's XML file does not carry.
Microsoft\Windows NT\CurrentVersion\WindowsSOFTWAREAppInit_DLLs and LoadAppInit_DLLs - a DLL injected into most processes.
Microsoft\Windows NT\CurrentVersion\WinlogonSOFTWAREUserinit, Shell and Notify. Anything appended here runs at logon with the user's rights and is a long-standing hijack point.
Microsoft\Windows Script Host\SettingsSOFTWAREWhether Windows Script Host is enabled, which decides if a .vbs or .js payload can run at all.
Microsoft\Windows\CurrentVersion\App PathsSOFTWAREHow a bare command name resolves to an executable. Change an entry and typing the name runs something else, with no path to give it away.
Microsoft\Windows\CurrentVersion\AuthenticationSOFTWARECredential providers, which load into the logon UI.
Microsoft\Windows\CurrentVersion\Authentication\Credential Provider FiltersSOFTWAREFilters that hide or allow credential providers on the logon screen. A filter DLL loads into LogonUI like a provider does.
Microsoft\Windows\CurrentVersion\Authentication\Credential ProvidersSOFTWARECredential provider CLSIDs. Each backing DLL loads into LogonUI and sees what is typed at the logon screen, so an unfamiliar one is a credential-theft lead.
Microsoft\Windows\CurrentVersion\Explorer\Browser Helper ObjectsSOFTWAREBrowser Helper Objects: COM DLLs Internet Explorer and Explorer load at start. Resolved through the CLSID to the DLL on disk.
Microsoft\Windows\CurrentVersion\Explorer\FileExtsSOFTWAREPer-extension handler choices. Change the handler for a common file type and opening an ordinary document runs something else.
Microsoft\Windows\CurrentVersion\Explorer\SharedTaskSchedulerSOFTWAREAnother Explorer-loaded COM list, and another autostart.
Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiersSOFTWAREIcon overlay handlers: DLLs Explorer loads into every folder view to draw sync and status badges. Explained in full: shell extensions
Microsoft\Windows\CurrentVersion\Explorer\StartupApprovedSOFTWARE, per-userWhether each autostart entry is actually allowed to launch, and when it was switched off. A Run value is a request; this is the answer. Without it every Run value reads as live persistence - on the system behind this page six of ten were disabled, two of them since February.
Microsoft\Windows\CurrentVersion\Explorer\User Shell FoldersSOFTWAREWhere Windows believes the user's Startup folder is. Repoint it and the Startup folder somebody inspects is not the one that runs.
Microsoft\Windows\CurrentVersion\Policies\Explorer\RunSOFTWAREA policy-backed autostart location, less watched than the ordinary one.
Microsoft\Windows\CurrentVersion\RunSOFTWARE, per-userThe classic autostart key. Every value runs at logon.
Microsoft\Windows\CurrentVersion\RunOnceSOFTWARE, per-userRuns once at the next logon and is then deleted, which is why an entry still present is worth reading closely.
Microsoft\Windows\CurrentVersion\RunServicesSOFTWAREA legacy autostart location that still executes.
Microsoft\Windows\CurrentVersion\RunServicesOnceSOFTWAREThe run-once form of the same legacy location.
Microsoft\Windows\CurrentVersion\SharedDLLsSOFTWAREReference counts Windows keeps for shared libraries. Mostly inventory, and occasionally the only surviving record that a DLL was ever installed.
Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoadSOFTWARECOM objects Explorer loads at startup, by CLSID.
Policies\Explorer\RunSOFTWAREThe same policy autostart, reached through the Policies hive path.
WOW6432Node\Classes\CLSIDSOFTWAREThe redirected 32-bit COM view as the live API presents it.
WOW6432Node\Microsoft\Active Setup\Installed ComponentsSOFTWAREThe 32-bit view of Active Setup on a 64-bit machine.
WOW6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32SOFTWAREThe 32-bit view of Drivers32: multimedia driver DLLs a 32-bit process loads through winmm.
WOW6432Node\Microsoft\Windows NT\CurrentVersion\WindowsSOFTWAREThe 32-bit AppInit location.
WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper ObjectsSOFTWAREThe 32-bit view of Browser Helper Objects, loaded by 32-bit Internet Explorer.
{ControlSet}\Control\LsaSYSTEMLSA configuration - authentication packages, notification packages, and the four class-name keys that hold the machine's boot key.
{ControlSet}\Control\Print\EnvironmentsSYSTEMPrint processors and drivers, another spooler-loaded DLL location.
{ControlSet}\Control\Print\MonitorsSYSTEMPrint monitor DLLs, loaded by the spooler as SYSTEM.
{ControlSet}\Control\Print\PrintersSYSTEMThe system view of the same printers.
{ControlSet}\Control\SafeBootSYSTEMServices and drivers that still start in Safe Mode - the boot people use to clean a machine, which is exactly why persistence is placed here.
{ControlSet}\Control\SecurityProvidersSYSTEMSecurity packages loaded by LSA.
{ControlSet}\Control\SecurityProviders\WDigestSYSTEMUseLogonCredential. Set to 1, plaintext credentials return to memory - a single DWORD with a large consequence.
{ControlSet}\Control\Session ManagerSYSTEMBootExecute and PendingFileRenameOperations - what runs before Windows starts, and what is moved or deleted at the next boot.
{ControlSet}\Control\Session Manager\AppCertDllsSYSTEMDLLs loaded into every process that calls CreateProcess. Rarely populated legitimately, so anything here is worth explaining.
{ControlSet}\Control\WindowsSYSTEMSystem-wide Windows settings, including error-mode behaviour.
{ControlSet}\ServicesSYSTEMEvery service and driver on the machine. The start type decides whether it runs at boot, and the image path says what runs.

Question 3: what was plugged into it?

USB history is spread across several keys that each hold a piece, and the piece most people want - when - is in the least accessible of them.

Table 5
KeyHolds
Enum\USBevery USB device by vendor and product, one subkey per physical unit
Enum\USBSTORmass storage specifically, keyed by serial number
MountPoints2per user: which volumes that user mounted, which ties a device to a person
MountedDevicesdrive letter assignments, which ties a device to a letter in other artifacts

The timestamps live under each device's Properties subkey, in {83da6326-97a6-4088-9453-a1923f573b29}, as four numbered values: 0064 install, 0065 first install, 0066 last arrival, 0067 last removal. They are DEVPROP_TYPE_FILETIME, which is not one of the twelve documented registry types, so a reader that only knows the twelve refuses them.

0066 is the connection, 0067 is the disconnection

Getting these the wrong way round reports the moment a device was unplugged as the moment it was attached. The tell is structural: a device still connected has no 0067 at all, so a "last connected" column that is empty for currently-attached devices has them swapped.

These keys deny even an administrator

The Properties subkeys are ACL'd such that an elevated administrator reading through the registry API is refused. Measured on a live machine: an API walk of Enum\USB reaches 110 keys where reading the same hive as a file reaches 868. A live tool that does not read the hive file reports no USB timestamps at all, and reports it as an absence of evidence.

Every key Crow-Eye reads for this question (14)

The full list, so the page can answer "is this key covered?" rather than leaving it open. A key shown as {ControlSet} is read as CurrentControlSet on a live machine and as the control set Select names in an offline hive.

Table 6
KeyHiveWhat it is for
Microsoft\Windows Portable Devices\DevicesSOFTWAREFriendly names and volume labels for portable devices, which is often the only human-readable name a device left behind.
Microsoft\Windows Search\VolumeInfoCacheSOFTWAREVolume labels and serials the search indexer has recorded.
Microsoft\Windows\CurrentVersion\Explorer\MountPoints2SOFTWAREVolumes this user has mounted, including network shares and removable drives, keyed by volume GUID.
Microsoft\Windows\CurrentVersion\Explorer\VolumeInfoCacheSOFTWAREExplorer's own cache of volume labels, including drives long removed.
MountedDevicesSYSTEMDrive letters and volume GUIDs mapped to the disk signature and partition offset behind them. This is what ties a physical disk to a machine.
{ControlSet}\Control\DeviceClassesSYSTEMDevices grouped by interface class, with the arrival records that pair with the Enum keys.
{ControlSet}\Control\FileSystemSYSTEMFilesystem behaviour, including whether last-access times are updated - which decides whether an access timestamp means anything at all.
{ControlSet}\Enum\SCSISYSTEMSCSI-enumerated devices, which is how some external enclosures appear.
{ControlSet}\Enum\SWD\WPDBUSENUMSYSTEMPortable devices - phones and cameras - as the WPD bus enumerates them.
{ControlSet}\Enum\USBSYSTEMEvery USB device the machine has enumerated, by vendor and product.
{ControlSet}\Enum\USBSTORSYSTEMUSB mass storage specifically - the key that answers 'what drive was plugged in'.
{ControlSet}\Enum\USB\{device_id}\{instance_id}\PropertiesSYSTEMThe per-device property store holding the connection timestamps. Its ACL denies even an elevated administrator through the API, so these values are readable only from the hive as a file.
{ControlSet}\Services\BTHPORT\Parameters\DevicesSYSTEMBluetooth devices that have been paired, with their addresses and names.
{ControlSet}\Services\usbstorSYSTEMThe USB storage driver's start type. Set to 4 it is disabled, which is both a hardening measure and a way to explain missing device history.

Question 4: where did the user go?

Explorer remembers, and the remembering is per user and per hive. Shellbags get a page of their own; the rest are MRU lists.

All of these — Shellbags, RecentDocs, the dialog MRUs, TypedPaths, RunMRU and the search history, together with what the user ran (UserAssist, BAM, DAM, FeatureUsage, the Compatibility Assistant) and the rest of the user-activity keys — are read together by the Charts button on each of their table tabs, which opens one User Activity dashboard: every source on one timeline, most-visited places, the volumes and shares each pointed at, and per-item detail. Each table is explained one by one below.

An MRU key holds numbered values and one ordering value. In older keys that is MRUList, a string of letters: on the reference system the RunMRU key holds 2 entries ordered ba. Newer keys use MRUListEx, four-byte indices terminated by 0xFFFFFFFF.

The value names are allocation order, not use order

Reading an MRU key's values in numeric order and reporting that as history is wrong, and it is wrong in a way that looks right: the entries are correct and their order is not. The ordering value is the only thing that says what was used most recently, and a parser that ignores it silently reorders the user's activity.

RecentDocs, OpenSaveMRU, LastVisitedMRU, TypedPaths, WordWheelQuery and the RDP client's history are all this shape. Several store shell items rather than strings, which is the same structure a Shellbag and a shortcut use.

That is where they stop being alike. One holds a shell item list to a file, one holds an application name and then a folder, one holds an application name and a window size with no path in it at all, and two hold nothing but a string - so a row from one supports a sentence a row from another does not. Explained in full: the MRU family

Every key Crow-Eye reads for this question (34)

The full list, so the page can answer "is this key covered?" rather than leaving it open. A key shown as {ControlSet} is read as CurrentControlSet on a live machine and as the control set Select names in an offline hive.

Table 7
KeyHiveWhat it is for
7-Zip\CompressionSOFTWARE7-Zip's recent archive and extraction paths.
Classes\Local Settings\Software\Microsoft\Windows\ShellNoRoam\BagMRUUsrClass.datThe pre-Windows-7 Shellbag tree inside UsrClass.dat. Rarely populated on a modern machine, which is exactly why a bag that does land here is worth noticing. All four Shellbag trees
Classes\Local Settings\Software\Microsoft\Windows\Shell\BagMRUUsrClass.datShellbags. Every folder opened in Explorer, including folders on drives removed years ago. All four Shellbag trees
FileZilla ClientSOFTWAREFileZilla configuration and site history.
Martin Prikryl\WinSCP 2\SessionsSOFTWARESaved WinSCP sessions, including hostnames and usernames.
Microsoft\Internet Explorer\TypedURLsSOFTWAREURLs typed into the address bar. Still written by parts of Windows long after anyone stopped using the browser.
Microsoft\Internet Explorer\TypedURLsTimeSOFTWAREThe timestamps for those typed URLs, in a separate key.
Microsoft\OfficeSOFTWAREOffice settings and recent-file lists.
Microsoft\Terminal Server ClientSOFTWARERemote desktop connections this user made, and to which hosts.
Microsoft\Windows\CurrentVersion\Applets\RegeditNTUSER.DATRegistry Editor's LastKey (the key open when it was closed) and its Favorites. Someone browsing the registry by hand leaves this behind. Explained in full: Regedit last key
Microsoft\Windows\CurrentVersion\CapabilityAccessManager\ConsentStoreSOFTWAREWhich applications hold consent for a capability - microphone, camera, location - and when each last used it. The registry's own record of surveillance-capable access.
Microsoft\Windows\CurrentVersion\ExplorerSOFTWAREThe Explorer root, parent of most per-user activity keys.
Microsoft\Windows\CurrentVersion\Explorer\AdvancedNTUSER.DATWhat this user chose to see in Explorer: Hidden, HideFileExt and ShowSuperHidden. ShowSuperHidden=1 is off by default and means protected OS files were made visible.
Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\CIDSizeMRUNTUSER.DATPrograms that opened an Open or Save dialog, newest first, with no path - the executable name only. Explained in full: CIDSizeMRU
Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedPidlMRUSOFTWAREThe folder each application last used in a file dialog, which links a program to a location.
Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRUSOFTWAREFiles chosen in an Open or Save dialog, as shell item lists.
Microsoft\Windows\CurrentVersion\Explorer\Map Network Drive MRUSOFTWARENetwork drives the user mapped by hand.
Microsoft\Windows\CurrentVersion\Explorer\RecentDocsSOFTWAREFiles opened recently, grouped by extension, ordered by MRUListEx.
Microsoft\Windows\CurrentVersion\Explorer\RunMRUSOFTWAREWhat was typed into the Run dialog, in use order.
Microsoft\Windows\CurrentVersion\Explorer\Shell Foldersper-userWhere the shell resolves each known folder to. The resolved half of User Shell Folders, which holds the unexpanded form.
Microsoft\Windows\CurrentVersion\Explorer\StartPage2NTUSER.DATProgramsCache: the Start menu's cached list of program shortcuts, one binary blob of shell items. Explained in full: ProgramsCache
Microsoft\Windows\CurrentVersion\Explorer\Taskbandper-userItems pinned to the taskbar, as a shell item list. Deliberate arrangement rather than incidental use.
Microsoft\Windows\CurrentVersion\Explorer\TypedPathsSOFTWAREPaths typed into the Explorer address bar - deliberate navigation, not clicking.
Microsoft\Windows\CurrentVersion\Explorer\WordWheelQuerySOFTWARETerms typed into Explorer's search box.
Microsoft\Windows\ShellNoRoam\BagMRUNTUSER.DATThe local-only Shellbag tree from the same era. A collection that takes only NTUSER.DAT gets these and misses the modern ones entirely. All four Shellbag trees
Microsoft\Windows\Shell\BagMRUNTUSER.DATThe roaming Shellbag tree, used before Windows 7 moved them to UsrClass.dat. All four Shellbag trees
RealVNCSOFTWAREVNC server configuration, including whether it accepts connections.
SimonTatham\PuTTY\SessionsSOFTWARESaved PuTTY sessions - hosts, users and ports somebody configured.
SimonTatham\PuTTY\SshHostKeysSOFTWARESSH host keys PuTTY has accepted, which is a record of hosts actually connected to rather than merely configured.
SysinternalsSOFTWAREEULA-accepted keys for Sysinternals tools. Their presence dates the first run of a tool that is often brought onto a machine deliberately.
TeamViewerSOFTWARETeamViewer configuration and connection history.
Trusted Documents\TrustRecordsSECURITYOffice documents the user chose to enable content in - a record of somebody clicking through a macro warning.
WinRAR\ArcHistorySOFTWAREArchives opened in WinRAR.
WinRAR\DialogEditHistory\ExtrPathSOFTWAREPaths archives were extracted to - where the contents of an archive actually landed.

Every user-activity table, one by one

Each table below is one tab in Crow-Eye, and each has an Anatomy button that opens its own section here. Its Charts button opens the User Activity dashboard, where it shares one timeline with Shellbags, the MRUs and every other source below. The shell-item tables (RecentDocs, the dialog MRUs, TypedPaths, RunMRU, search, MountPoints2) are explained on the Shell Items page.

UserAssist

Programs and shortcuts this user launched through Explorer, with how often and for how long they had focus. The value names are ROT13-encoded paths (why, and what that breaks).

FieldDetail
KeyNTUSER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{GUID}\Count; {CEBFF5CD-...} holds executables, {F4E57C4B-...} shortcuts
Value data (Windows 7+)A 72-byte record: run count at offset 4, focus count at 8, focus time in milliseconds at 12, last execution FILETIME at 60 (byte map above)
NamesA path may start with a known-folder GUID instead of a drive ({6D809377-...} is Program Files); UEME_CTL... values are UserAssist's own counters, not programs
TimestampPer entry: the last execution time
ProvesThis user launched it through the shell, the count and the last time
Does not proveExecution from a command line or a service, which UserAssist never sees
In Crow-EyeTable UserAssist: decoded path, run count, focus count, focus time, last execution, user
On the User Activity dashboardSource UserAssist, dated by last execution; the counters are left out

BAM, the background activity moderator

The kernel's record of the last time each program ran, per user SID (how BAM works).

FieldDetail
KeySYSTEM\{ControlSet}\Services\bam\State\UserSettings\<SID> (Windows 10 1709 and later; earlier builds used Services\bam\UserSettings)
ValuesName: a device path (\Device\HarddiskVolume3\...) or a Store app ID. Data: 24 bytes, a FILETIME first. Version and SequenceNumber are bookkeeping, not programs
TimestampPer entry: the last execution
ProvesThat binary ran under that SID, most recently at that time - including programs never launched from Explorer
Does not proveEarlier runs: one time per binary, and entries are pruned after a short window
In Crow-EyeTable BAM: process path, app name, SID (resolved to a user), last execution
On the User Activity dashboardSource BAM, dated by last execution

A device path is not a drive letter

\Device\HarddiskVolume3 is the third volume the kernel numbered at boot, not C:. Map it through the partition layout before writing a drive letter in a report.

DAM, the desktop activity moderator

The same record as BAM, kept by the Desktop Activity Moderator. It exists only on devices that support Modern Standby (connected standby), so on most desktops the table is empty - and that is not a gap.

FieldDetail
KeySYSTEM\{ControlSet}\Services\dam\State\UserSettings\<SID>
ValuesSame format as BAM: a FILETIME first; some builds also keep an execution count
TimestampPer entry: the last execution
ProvesThat binary ran under that SID on a Modern Standby device
Does not proveAnything on a machine without Modern Standby, where Windows never writes it
In Crow-EyeTable DAM
On the User Activity dashboardSource DAM

MUICache

Friendly names Explorer read from executables' version resources - which happens when the shell displays or launches them.

FieldDetail
KeyUsrClass.dat\Local Settings\Software\Microsoft\Windows\Shell\MuiCache (Vista and later)
ValuesName: <path>.FriendlyAppName or .ApplicationCompany. Data: the text
TimestampNone per entry
ProvesThe shell handled that executable for this user, usually because it was launched
Does not proveWhen, or how often
In Crow-EyeTable MUICache: path, application name, company
On the User Activity dashboardSource MUICache, undated: listed under All items

RecentApps

Windows 10's early record of recently used apps and the files each opened (builds 1507 to 1607; later builds dropped it).

FieldDetail
KeyNTUSER\Software\Microsoft\Windows\CurrentVersion\Search\RecentApps\{GUID}, with RecentItems subkeys
ValuesAppId, AppPath, LaunchCount, LastAccessedTime (FILETIME)
TimestampPer app: the last access
ProvesThe app was used, how often, and when last
Does not proveAnything on builds that never wrote the key
In Crow-EyeTable RecentApps
On the User Activity dashboardSource RecentApps

FeatureUsage (taskbar)

Per-program counters kept by the taskbar (Windows 10 1903 and later).

FieldDetail
KeyNTUSER\Software\Microsoft\Windows\CurrentVersion\Explorer\FeatureUsage, subkeys AppSwitched (switched to from the taskbar), AppLaunch (launched from a pin), ShowJumpView (jump list opened), AppBadgeUpdated, TrayButtonClicked
ValuesName: a program path or AppUserModelID. Data: a DWORD count
TimestampOnly each subkey's last-write time - one upper bound shared by every counter in it
ProvesThe user interacted with that program through the taskbar, that many times
Does not proveWhen any one interaction happened
In Crow-EyeTable FeatureUsage: usage type, program, count, key upper bound
On the User Activity dashboardSource FeatureUsage, undated: plotting every counter on the subkey's day would be a false spike

The compatibility assistant store (PCA)

Programs the Program Compatibility Assistant watched because the user ran them - installers and downloaded tools especially.

FieldDetail
KeyNTUSER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store
ValuesName: the full path of the program. Data: a binary record (Crow-Eye keeps its size)
TimestampOnly the key's last-write time
ProvesThis user ran that executable - the path survives after the file is deleted
Does not proveWhen; on Windows 11 22H2 and later PCA also keeps text logs in C:\Windows\appcompat\pca
In Crow-EyeTable CompatibilityAssistant
On the User Activity dashboardSource Compatibility Assistant, undated

File associations (FileExts)

Which programs the user opened each file type with, and which one they chose as the default.

FieldDetail
KeyNTUSER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\<.ext> with OpenWithList (an MRU of programs), OpenWithProgids and UserChoice (the default)
TimestampEach subkey's last-write time
ProvesThis user opened that type with that program at least once, or set it as the default
Does not proveWhich file
In Crow-EyeTable file_exts: extension, list type, program or ProgID
On the User Activity dashboardSource File associations, undated

An unusual program in OpenWithList is worth a look

.001 opened with FTK Imager, or .ps1 with Notepad, says what the user did with a file type even when the file itself is gone.

ProgramsCache (Start menu)

The Start menu's cached list of programs, stored as shell items.

FieldDetail
KeyNTUSER\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage2, value ProgramsCache
ValuesOne binary value: a list of shell items. Crow-Eye records its presence and size, not its decoded entries
TimestampNone per entry
ProvesThe value exists for this user; decoded, it lists programs the Start menu offered
Does not proveExecution
In Crow-EyeTable programs_cache
On the User Activity dashboardSource ProgramsCache, undated

Registry Editor: last key and favourites

Where Registry Editor was looking when it was last closed, and the keys saved as favourites.

FieldDetail
KeyNTUSER\Software\Microsoft\Windows\CurrentVersion\Applets\Regedit: value LastKey, subkey Favorites
TimestampThe key's last-write time, close to when Registry Editor was last closed
ProvesRegistry Editor was used by this user - a LastKey on a Run key or a service is worth a look
Does not proveWhat was changed
In Crow-EyeTable regedit_lastkey
On the User Activity dashboardSource Regedit last key

TypedURLs

Addresses typed into the Internet Explorer (and Explorer) address bar.

FieldDetail
KeysNTUSER\Software\Microsoft\Internet Explorer\TypedURLs (url1 ... url25, url1 newest) and TypedURLsTime (a FILETIME per urlN, Windows 8 and later)
TimestampPer entry when TypedURLsTime exists; otherwise only the key's write time
ProvesThe user typed that address
Does not proveBrowsing in other browsers - see the browser page
In Crow-EyeTable BrowserHistory (the registry tab of that name)
On the User Activity dashboardSource TypedURLs, dated by TypedURLsTime when present

Explained in full: browser forensics

Remote desktop client history

Hosts this user connected to with Remote Desktop.

FieldDetail
KeysNTUSER\Software\Microsoft\Terminal Server Client\Default (MRU0 ... MRU9) and \Servers\<host> with UsernameHint
TimestampEach key's last-write time
ProvesAn outbound Remote Desktop connection was attempted to that host, and with which account name
Does not proveThat it succeeded - check the target's logon events (4624 type 10)
In Crow-EyeTable RDPClientMRU
On the User Activity dashboardSource RDPClientMRU; every row counts as network activity

Office recent files and trusted documents

Documents opened in Word, Excel and PowerPoint, and the documents the user let run active content.

FieldDetail
KeysNTUSER\Software\Microsoft\Office\<version>\<app>\File MRU and Place MRU (Microsoft 365 adds User MRU\<id>\...); ...\Security\Trusted Documents\TrustRecords
ValuesMRU items look like [F00000000][T01D...][O00000000]*C:\path; the T field is a FILETIME in hex - the last open. TrustRecords: value name = document path
TimestampPer MRU entry (the T field); TrustRecords carry a FILETIME in their data
ProvesThe document was opened in Office; a trust record means the user clicked Enable Editing or Enable Content (a trailing FF FF FF 7F is widely documented as macros enabled)
Does not proveWhat the document contained
In Crow-EyeTable OfficeDocuments (TrustRecords included)
On the User Activity dashboardSource Office MRU

Application MRUs (PuTTY, WinSCP, WinRAR, 7-Zip, ...)

What third-party tools remember, read from their own keys.

FieldDetail
PuTTYSoftware\SimonTatham\PuTTY\Sessions (saved sessions) and SshHostKeys (every SSH host this user accepted a key for)
WinSCPSoftware\Martin Prikryl\WinSCP 2\Sessions: saved file-transfer sessions
WinRARSoftware\WinRAR\ArcHistory (archives opened) and DialogEditHistory\ExtrPath (extraction folders)
7-ZipSoftware\7-Zip\Compression: archive history
SysinternalsSoftware\Sysinternals\<tool> EulaAccepted: the tool ran at least once for this user
TeamViewer, FileZilla, RealVNCConfiguration keys - presence means the tool was installed or used by this user
TimestampEach key's last-write time
ProvesRemote access, file transfer or archiving tools were used, and where they pointed
In Crow-EyeTable ApplicationArtifacts
On the User Activity dashboardSource App MRUs

Camera, microphone and location use (ConsentStore)

When each app last used the camera, microphone or location, with a start and a stop time (Windows 10 1903 and later).

FieldDetail
KeysSOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\ConsentStore\<capability> and the same path in NTUSER; Store apps by package name, desktop programs under NonPackaged with # in place of \
ValuesLastUsedTimeStart, LastUsedTimeStop (FILETIMEs), Value (Allow / Deny)
TimestampPer app: the start and stop of its last use
ProvesThat program had the camera, microphone or location in use between those two times
Does not proveWhat was recorded, or earlier uses
In Crow-EyeTable app_permissions: capability, app, permission, last used start and stop
On the User Activity dashboardSource Camera / mic / location, dated by last-use start

Question 5: what was this machine, and what was it connected to?

Identity and network answer the questions that come up when an image arrives with no context: whose machine is this, what was it called, what network was it on, when was it installed.

Table 8
KeyAnswers
ComputerNamethe machine name, and note there are two: the active one and the one pending a reboot
MachineGuida stable identifier that survives renames
NetworkList\Profilesevery network joined, with first and last connection, and the gateway's MAC
ProfileListSID to profile path, which is how any per-user artifact gets a name attached
TimeZoneInformationthe offset every local timestamp on the machine was written in

The gateway MAC in NetworkList places a machine physically

Each network profile records the default gateway's MAC address. That identifies a specific piece of hardware, so a laptop's profile list is a record of which physical networks it was carried to and when it first and last saw each. It is one of the few registry artifacts that speaks to location.

SIDs resolve against the evidence, not against the examining machine

The registry stores SIDs, not names. Resolving them with the API on the examiner's workstation returns that workstation's accounts, and a local SID that happens to collide gets a confident wrong name attached. The mapping has to come from the image's own SAM and ProfileList.

Every key Crow-Eye reads for this question (53)

The full list, so the page can answer "is this key covered?" rather than leaving it open. A key shown as {ControlSet} is read as CurrentControlSet on a live machine and as the control set Select names in an offline hive.

Table 9
KeyHiveWhat it is for
Microsoft\CryptographySOFTWAREMachineGuid, which identifies this installation across rebuilds of almost everything else.
Microsoft\Windows Defender\ExclusionsSOFTWAREPaths, extensions and processes Defender ignores. An exclusion added by an intruder is a quiet way to make a payload invisible.
Microsoft\Windows NT\CurrentVersionSOFTWAREThe Windows build, edition, install date and registered owner.
Microsoft\Windows NT\CurrentVersion\NetworkCardsSOFTWAREThe adapter inventory by installation index. Names cards that no longer have an interface, which is how a removed adapter leaves a trace.
Microsoft\Windows NT\CurrentVersion\NetworkList\ProfilesSOFTWARENetworks the evidence machine has joined, with first and last connection times.
Microsoft\Windows NT\CurrentVersion\NetworkList\Signatures\ManagedSOFTWAREDomain networks, identified by their gateway MAC - which places a machine on a physical network rather than merely naming one.
Microsoft\Windows NT\CurrentVersion\NetworkList\Signatures\UnmanagedSOFTWAREThe same signatures for non-domain networks - home and public Wi-Fi.
Microsoft\Windows NT\CurrentVersion\ProfileListSOFTWAREEvery user profile by SID, with its path. This is what turns a SID in another artifact into a person.
Microsoft\Windows NT\CurrentVersion\SystemRestoreSOFTWAREWhether restore points are being created, and therefore whether earlier hive copies exist to compare against.
Microsoft\Windows Search\GatherSOFTWAREWhat the search indexer is scoped to crawl, and therefore which files could appear in its database at all.
Microsoft\Windows\CurrentVersionSOFTWAREPer-user Windows settings, parent of the Run and Explorer keys.
Microsoft\Windows\CurrentVersion\Group Policy\HistorySOFTWAREGroup policy objects that have been applied, and when - which says what domain the evidence machine answered to.
Microsoft\Windows\CurrentVersion\Internet SettingsSOFTWAREProxy configuration, which decides where a machine's traffic went.
Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMapper-userHosts, protocols and ranges assigned to a security zone. A host moved into Trusted Sites runs content every other zone would block.
Microsoft\Windows\CurrentVersion\Policies\Attachmentsper-userAttachment handling, including SaveZoneInformation. Suppressed, downloaded files lose their Mark of the Web and stop warning anyone.
Microsoft\Windows\CurrentVersion\Policies\SystemSOFTWAREUAC configuration, including the consent prompt behaviour that a bypass depends on.
Microsoft\Windows\CurrentVersion\UninstallSOFTWAREInstalled software, with publisher, version and install date.
Microsoft\Windows\CurrentVersion\WINEVT\ChannelsSOFTWAREEvery event log channel, whether it is enabled and where its file lives. A disabled channel explains a silence that would otherwise look like nothing happened.
Microsoft\Windows\CurrentVersion\WindowsUpdateSOFTWAREUpdate client state, including when it last checked and installed.
Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto UpdateSOFTWAREAutomatic update policy - whether patches were being applied at all.
Policies\Microsoft\Windows DefenderSOFTWAREDefender policy, including whether it has been disabled outright.
Policies\Microsoft\Windows Defender\ExclusionsSOFTWAREThe policy-enforced form of the same exclusions.
Policies\Microsoft\Windows Defender\Real-Time ProtectionSOFTWAREReal-time protection settings - the switch that turns off live scanning.
Policies\Microsoft\Windows\PowerShell\ModuleLoggingSOFTWAREWhether PowerShell module activity is logged.
Policies\Microsoft\Windows\PowerShell\ScriptBlockLoggingSOFTWAREWhether PowerShell records the script blocks it executes. Off, a whole class of evidence was never created.
SelectSYSTEMWhich ControlSet is current. An offline hive has no CurrentControlSet, so this value is what resolves it.
SetupSYSTEMSetup and upgrade history, which dates the build the machine came from.
WOW6432Node\Microsoft\WindowsSOFTWAREThe 32-bit view of per-user Windows settings.
WOW6432Node\Microsoft\Windows NTSOFTWAREThe 32-bit view of the system settings tree.
WOW6432Node\Microsoft\Windows\CurrentVersion\UninstallSOFTWAREThe 32-bit software inventory on a 64-bit machine.
{ControlSet}\Control\BackupRestore\FilesNotToSnapshotSYSTEMFiles excluded from shadow copies. An addition here removes something from every future snapshot.
{ControlSet}\Control\ComputerName\ActiveComputerNameSYSTEMThe name in force now. The two differ after a rename that has not rebooted, and the difference is itself a finding.
{ControlSet}\Control\ComputerName\ComputerNameSYSTEMThe machine name as it will be after the next reboot.
{ControlSet}\Control\CrashControlSYSTEMCrash dump settings, and whether a dump would exist to collect.
{ControlSet}\Control\DeviceGuardSYSTEMVirtualisation-based security and Credential Guard. Whether LSASS was protected decides whether credential theft was even possible.
{ControlSet}\Control\NetworkSYSTEMNetwork adapters and their bindings.
{ControlSet}\Control\Network\{4d36e972-e325-11ce-bfc1-08002be10318}SYSTEMThe network adapter class: each adapter GUID with the connection name shown in ncpa.cpl, so a Tcpip interface GUID elsewhere in the case can be named.
{ControlSet}\Control\NetworkProvider\OrderSYSTEMThe order network providers are consulted in.
{ControlSet}\Control\Nls\LanguageSYSTEMThe system locale and the language Windows was installed in - an attribution signal that survives almost everything else.
{ControlSet}\Control\ProductOptionsSYSTEMProduct type - whether this is a workstation, a server or a domain controller.
{ControlSet}\Control\Session Manager\EnvironmentSYSTEMSystem-wide environment variables, including PATH - which decides which binary a bare command resolves to.
{ControlSet}\Control\Session Manager\Memory ManagementSYSTEMPaging behaviour, including whether the page file is cleared at shutdown.
{ControlSet}\Control\Session Manager\PowerSYSTEMPower and fast startup. HiberbootEnabled decides whether a shutdown was a real one, and therefore whether ShimCache was flushed at all.
{ControlSet}\Control\Terminal ServerSYSTEMWhether remote desktop is enabled at all.
{ControlSet}\Control\Terminal Server\WinStations\RDP-TcpSYSTEMThe RDP listener - its port, and whether network level authentication is required.
{ControlSet}\Control\TimeZoneInformationSYSTEMThe machine's timezone and bias. Needed to read every local timestamp the evidence contains, including the DOS times inside shell items.
{ControlSet}\Control\hivelistSYSTEMWhere every loaded hive lives on disk - the map an image parser uses to find the files it has not been handed.
{ControlSet}\Services\Dnscache\ParametersSYSTEMDNS client settings, including whether the resolver cache is running - which decides whether a lookup left any local trace to find.
{ControlSet}\Services\EventLogSYSTEMEvent log service configuration and per-log retention.
{ControlSet}\Services\LanmanServer\SharesSYSTEMShares the evidence machine offers, and the paths behind them.
{ControlSet}\Services\SharedAccess\ParametersSYSTEMFirewall rules and internet connection sharing configuration.
{ControlSet}\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRulesSYSTEMEvery Windows Firewall rule as a pipe-delimited string: direction, action, program, ports. A rule allowing inbound traffic to an unusual program is a lead.
{ControlSet}\Services\Tcpip\Parameters\InterfacesSYSTEMPer-interface IP configuration, including DHCP leases and the server that issued them.

What the registry supports, and what it does not

The five questions above each carry their own warning where it belongs, in the artifact it applies to. Four limits are not about any one key — they are properties of the registry itself, and they apply to every finding on this page.

A write time belongs to the key, not to any value under it

The registry timestamps keys. It does not timestamp values. A key holding forty values has one last-write time, and any one of those forty writes could have set it — as could a write that only changed a value already present, or a subkey being created. So a key time is an upper bound on everything beneath it, shared by all of it. Reporting "this value was written at 14:02" is a claim the registry cannot support unless the key holds exactly one value.

Presence is configuration, not execution

This is the error the whole of Question 2 is written against, and it generalises. A Run key entry, a service, a scheduled-task registration and a COM registration all say the same thing: the machine was told to do something. None of them says it happened. The proof of execution is somewhere else — Prefetch, an event log, an AmCache entry with a real run time beside it.

A hive on disk and a hive in memory are not the same hive

Windows does not write every change straight into the hive file. Changes land in the transaction logs (.LOG1, .LOG2) and are merged later, so a hive file copied from a running machine can be missing the most recent writes — including the ones an intruder made minutes ago. Reading the live registry through the API sees the merged view; copying the file may not. When the two disagree, the logs are the difference, and they are part of the evidence rather than a nuisance.

Deleted does not mean gone, and present does not mean current

A deleted key or value is unlinked, not erased: its cell is marked free and its contents survive until that space is reused, which is why a recovered value can be read long after it was removed. The same property runs the other way. A key that exists may be a leftover from software uninstalled years ago, written once and never touched since — the registry keeps what nobody cleaned up, and says nothing about whether it still matters.

What it is genuinely good for: answering which question. No other artifact on a Windows machine spans execution, persistence, device history, user navigation and machine identity in one container, with the same acquisition and the same parser. The five questions above are the shape of that strength: the registry is rarely the only evidence for a finding, and it is very often the first place the finding is visible.

What Crow-Eye does with all of this

Seventy-odd tables, one per artifact, named for what they hold. Both acquisition routes - the live registry through the API, and the hive files through a shadow copy, raw disk or a backup-privileged export - produce the same tables, so a case has the same shape either way. Where an artifact needs a decoder rather than a read, that decoder is shared: the same code reads a shell item whether it came from a Shellbag, a Jump List or a shortcut. Explained in full: Jump Lists

Deleted keys and values are carved from the hive's freed cells and marked (deleted) in a column of their own, with the key path reconstructed where the parent chain survives and left empty where it does not. And every hive's transaction logs are replayed before parsing, because a hive read from a running machine is mid-transaction by default and its most recent changes are in the log rather than the file.

The registry internals guide is the companion to this page: it explains the file this evidence sits in, and why several of the behaviours above are structural rather than optional.

How the registry's artifacts changed across Windows

Each row below records a change that alters what a reader may conclude, not only how the bytes are arranged. A parser written against one Windows release returns nothing against another, and does so without raising an error.

Table 10
WindowsWhat changedWhat it means for a reader
3.1REG.DAT - one file, file associations onlyThe registry begins as a replacement for WIN.INI.
95 and NTThe hive format this page describes, split into several filesSYSTEM, SOFTWARE, NTUSER.DAT. The container has not fundamentally changed since.
VistaTransaction logs become mandatory; UsrClass.dat takes over ShellbagsA hive on disk may be missing its most recent changes until the logs are replayed.
8BAM and DAM arriveThe kernel starts keeping its own per-executable timestamps, which is the most reliable execution artifact in the registry.
10 and 11AppCompatCache loses its execution flag; AmCache moves to the Inventory* schemaTwo of the three registry execution artifacts change meaning. The literature mostly did not.

Reference

Value types, including the ones Microsoft did not document

Table 11
TypeNameWhat it holds
1REG_SZA string. Most of the registry.
3REG_BINARYBytes with no declared meaning - every map above is one of these.
4REG_DWORD32-bit integer, usually stored inline in the record.
7REG_MULTI_SZNull-separated strings, double null at the end.
11REG_QWORD64-bit integer.
0xFFFF0010DEVPROP_TYPE_FILETIMENot one of the twelve. Eight bytes, and it is where USB connection times live.
0xFFFF0012DEVPROP_TYPE_STRINGUTF-16 text under a device key.
0xFFFF000DDEVPROP_TYPE_GUIDSixteen bytes.

Which key answers which question

Table 12
QuestionKeyCaveat
What ran, from the shellUserAssistExplorer launches only. Nothing from a console or a service.
What ran, per the kernelbam\State\UserSettingsRoughly one week of history, then cleared.
What was examinedAppCompatCacheNot execution. Written at shutdown.
What is installedAmCache Inventory*Presence, not execution. Explained in full: AmCache
What persistsRun, RunOnce, services, TaskCachePersistence is not execution - it says what is scheduled, not what happened.
What was plugged inEnum\USBSTOR, MountedDevicesConnection times live in Properties, which denies even an elevated administrator through the API.
Where the user wentShellbags, RecentDocs, MRU keysMRUListEx is the only thing recording order.

Anti-forensic handling, and what survives it

The preceding sections describe what intact keys support. This section describes the registry after an attempt to remove or evade it, which is the condition in which it is frequently encountered. In most rows the attempt leaves a trace of its own.

Table 13
TechniqueWhat is doneWhat survives
Deleting a keyThe key is unlinked from its parent.The cell is freed, not erased. Name, timestamp and values usually survive until something allocates over them - which is what carving recovers.
Clearing UserAssistThe Count subkeys are emptied.An account with a login history and an empty UserAssist is an anomaly. BAM and Prefetch are unaffected and answer the same question.
Renaming rather than deletingA persistence value is renamed to look legitimate.The key's last-written timestamp still moves. A Run key whose write time is far from the software's install date is worth explaining.
Loosening permissionsA persistence key's ACL is changed so a non-administrator can write it.The key stops sharing its siblings' security descriptor and gets its own. Visible structurally without reading a single ACL - see the internals guide.
Operating in a live-only windowEverything is done in volatile keys.Volatile keys are never written to a file, so an offline image cannot contain them. This is one of the few things a live parse sees and an image genuinely does not.