Monitoring Registry Keys on a Windows Server

Windows Server
9.7
9.8
https://kb.netwrix.com/4937
Copy Article URL Copied

Here is the full list of standard registry keys that Netwrix Auditor will monitor out of the box if state-in-time data collection is enabled for a Windows Server.
NOTE: To monitor custom registry keys, follow the procedure described here.

Hardware
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces(|\\.*)
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}(|\\.*)
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}(|\\.*)
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002BE10318}(|\\.*)
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services(|\\.*)
General
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\CrashControl(|\\.*)
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CrashControl(|\\.*)
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\CrashControl(|\\.*)
  • HKEY_LOCAL_MACHINE\Software\WOW6432NODE\Microsoft\Windows NT\CurrentVersion(|\\.*)
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion(|\\.*)
Software
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL(|\\.*)
  • HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL(|\\.*)
Services
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services(|\\.*)
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services(|\\.*)

RegistryFileSharing
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanServer\Shares(|\\.*)
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\LanmanServer\Shares(|\\.*)
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\LanmanServer\Shares(|\\.*)

RegistryImportantServices
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ERSvc(|\\.*)
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ERSvc(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\ERSvc(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\FastUserSwitchingCompatibility(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\FastUserSwitchingCompatibility(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\FastUserSwitchingCompatibility(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetDDE(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NetDDE(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\NetDDE(|\\.*)
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetDDEdsdm(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NetDDEdsdm(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\NetDDEdsdm(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SSDPSRV(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SSDPSRV(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SSDPSRV(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Schedule(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Schedule(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Schedule(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WebClient(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WebClient(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\WebClient(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WmiApSrv(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WmiApSrv(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\WmiApSrv(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\upnphost(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\upnphost(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\upnphost(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AFD(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AFD(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\AFD(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Alerter(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Alerter(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Alerter(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AppMgmt(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AppMgmt(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\AppMgmt(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AppMgr(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AppMgr(|\\.*)

  • HKEY_LOCAL_MACHINE(|\\.*)SYSTEM\ControlSet002\Services\AppMgr(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Appmon(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Appmon(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Appmon(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BINLSVC(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\BINLSVC(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\BINLSVC(|\\.*)
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Browser(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Browser(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Browser(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Cdrom(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Cdrom(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CiSvc(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\CiSvc(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\CiSvc(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Clipsrv(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Clipsrv(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Clipsrv(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\Application(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\Application(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Security(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\Security(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\Security(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\System(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\System(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Fax(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Fax(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Fax(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\HTTPFilter(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\HTTPFilter(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\HTTPFilter(|\\.*)
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IISADMIN(|\\.*)
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\IISADMIN(|\\.*)
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\IISADMIN(|\\.*)
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IPSEC(|\\.*)
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\IPSEC(|\\.*)
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\IPSEC(|\\.*)
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanManServer\Parameters(|\\.*)
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\LanManServer\Parameters(|\\.*)
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\LanManServer\Parameters(|\\.*)
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters(|\\.*)
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\LanmanWorkstation\Parameters(|\\.*)
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\LanmanWorkstation\Parameters(|\\.*)
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LicenseService(|\\.*)
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\LicenseService(|\\.*)
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\LicenseService(|\\.*)
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSDTC(|\\.*)
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MSDTC(|\\.*)
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\MSDTC(|\\.*)
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSFtpsvc(|\\.*)
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MSFtpsvc(|\\.*)
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\MSFtpsvc(|\\.*)
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MacFile(|\\.*)
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MacFile(|\\.*)
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\MacFile(|\\.*)
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MacPrint(|\\.*)
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MacPrint(|\\.*)
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\MacPrint(|\\.*)
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Messenger(|\\.*)
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Messenger(|\\.*)
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Messenger(|\\.*)
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MrxSmb(|\\.*)
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MrxSmb(|\\.*)
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\MrxSmb(|\\.*)
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NTDS(|\\.*)
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NTDS(|\\.*)
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\NTDS(|\\.*)
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NWCWorkstation(|\\.*)
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NWCWorkstation(|\\.*)
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\NWCWorkstation(|\\.*)
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetBT(|\\.*)
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NetBT(|\\.*)
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\NetBT(|\\.*)
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Netlogon(|\\.*)
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Netlogon(|\\.*)
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Netlogon(|\\.*)
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Netman(|\\.*)
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Netman(|\\.*)
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Netman(|\\.*)
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NntpSvc(|\\.*
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NntpSvc(|\\.*)
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\NntpSvc(|\\.*)
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NtFrs(|\\.*)
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NtFrs(|\\.*)
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\NtFrs(|\\.*)
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\POP3Svc(|\\.*)
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\POP3Svc(|\\.*)
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\POP3Svc(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RDSessMgr(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RDSessMgr(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\RDSessMgr(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RasAuto(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RasAuto(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\RasAuto(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RasMan(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RasMan(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\RasMan(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteAccess(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RemoteAccess(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\RemoteAccess(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RemoteRegistry(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RemoteRegistry(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\RemoteRegistry(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Remote_Storage_Server(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Remote_Storage_Server(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Remote_Storage_Server(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Remote_Storage_User_Link(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Remote_Storage_User_Link(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Remote_Storage_User_Link(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RpcLocator(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RpcLocator(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\RpcLocator(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SMTPSVC(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SMTPSVC(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SMTPSVC(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SNMPTRAP(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SNMPTRAP(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SNMPTRAP(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SNMP(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SNMP(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SNMP(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SharedAccess(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Spooler(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Spooler(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Spooler(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrvcSurg(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SrvcSurg(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SrvcSurg(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TapiSrv(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TapiSrv(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\TapiSrv(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Tcpip(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TermService(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TermService(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\TermService(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TlntSvr(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TlntSvr(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\TlntSvr(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W3SVC(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\W3SVC(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\W3SVC(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WZCSVC(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WZCSVC(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\WZCSVC(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\helpsvc(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\helpsvc(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\helpsvc(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ldap(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ldap(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\ldap(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mnmsrvc(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\mnmsrvc(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\mnmsrvc(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tftpd(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\tftpd(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\tftpd(|\\.*)

RegistryOSSecurity
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet00\Control\FileSystem(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\FileSystem(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\FileSystem(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\NetworkProvider(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\NetworkProvider(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\NetworkProvider(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Print\Providers\LanMan Print Services(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Providers\LanMan Print Services(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Print\Providers\LanMan Print Services(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurePipeServers(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SecurePipeServers(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\SecurePipeServers(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Environment(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager\Environment(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Session Manager\Environment(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SessionManager\SubSystems\(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Session Manager\SubSystems(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager\Memory Management(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Session Manager\Memory Management(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Executive(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager\Executive(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Session Manager\Executive(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\KnownDLLs(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager\KnownDLLs(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Session Manager\KnownDLLs(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Windows(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Windows(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Windows(|\\.*)

  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options(|\\.*)

  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options(|\\.*)

RegistryPatches
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\Microsoft\Windows NT\CurrentVersion\Hotfix(|\\.*)

  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix(|\\.*)

  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages(|\\.*)

RegistryRemoteDesktop
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Terminal Server\WinStations\RDP-Tcp(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Terminal Server\WinStations\RDP-Tcp(|\\.*)

  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\Policies\Microsoft\Windows NT\Terminal Services(|\\.*)

RegistrySecurity
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\Microsoft\DrWatson(|\\.*)

  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DrWatson(|\\.*)

  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\Microsoft\Driver Signing(|\\.*)

  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Driver Signing(|\\.*)

  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\Microsoft\Non-Driver Signing(|\\.*)

  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Non-Driver Signing(|\\.*)

  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\Microsoft\MSDTC(|\\.*)

  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSDTC(|\\.*)

  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\Microsoft\NetDDE(|\\.*)

  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NetDDE(|\\.*)

  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\Microsoft\Windows\CurrentVersion\Policies\Explorer(|\\.*)

  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer(|\\.*)

  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\Microsoft\Windows\CurrentVersion\Policies\System(|\\.*)

  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System(|\\.*)

  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\Microsoft\Windows NT\CurrentVersion\Explorer\BitBucket(|\\.*)

  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Explorer\BitBucket(|\\.*)

  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\Microsoft\Windows NT\CurrentVersion\Group Policy(|\\.*)

  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Group Policy(|\\.*)

  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\Microsoft\Windows NT\CurrentVersion\Installer(|\\.*)

  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Installer(|\\.*)

  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\Microsoft\Windows NT\CurrentVersion\Policies\Explorer(|\\.*)

  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Policies\Explorer(|\\.*)

  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\Microsoft\Windows NT\CurrentVersion\Policies\System(|\\.*)

  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Policies\System(|\\.*)

  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\Microsoft\Windows NT\CurrentVersion\policies\Network(|\\.*)

  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\policies\Network(|\\.*)

  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\Microsoft\Windows NT\CurrentVersion\policies\Ratings(|\\.*)

  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\policies\Ratings(|\\.*)

  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\Microsoft\Windows NT\CurrentVersion\policies\system\(|\\.*)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\policies\system\(|\\.*)
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\Microsoft\Windows NT\CurrentVersion\AEDebug\(|\\.*)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AEDebug\(|\\.*)
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\Microsoft\Windows NT\CurrentVersion\AsrCommands\(|\\.*)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AsrCommands(|\\.*)

  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\Microsoft\Windows NT\CurrentVersion\Perflib(|\\.*)

  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Perflib(|\\.*)

  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\Microsoft\WindowsNT\CurrentVersion\SeCEdit(|\\.*)

  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SeCEdit(|\\.*)

  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\Microsoft\Windows NT\CurrentVersion\Setup\RecoveryConsole(|\\.*)

  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Setup\RecoveryConsole(|\\.*)

  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\Microsoft\Windows NT\CurrentVersion\Winlogon(|\\.*)

  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon(|\\.*)

  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\Policies\Microsoft\PCHealth\ErrorReporting(|\\.*)

  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PCHealth\ErrorReporting(|\\.*)

  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\Policies\Microsoft\Conferencing(|\\.*)

  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Conferencing(|\\.*)

  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\Policies\Microsoft\EventViewer(|\\.*)

  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\EventViewer(|\\.*)

  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\Policies\Microsoft\Messenger\Client(|\\.*)

  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Messenger\Client(|\\.*)

  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\Policies\Microsoft\SearchCompanion(|\\.*)

  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SearchCompanion(|\\.*)

  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\Policies\Microsoft\SystemCertificates\AuthRoot(|\\.*)

  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\AuthRoot(|\\.*)

  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\Policies\Microsoft\W32time\Parameters(|\\.*)

  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\W32time\Parameters(|\\.*)

  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\Policies\Microsoft\Windows NT\CurrentVersion\Winlogon(|\\.*)

  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\CurrentVersion\Winlogon(|\\.*)

  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\Policies\Microsoft\Windows NT\DCOM(|\\.*)

  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DCOM(|\\.*)

  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\Policies\Microsoft\Windows NT\IIS(|\\.*)

  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\IIS(|\\.*)

  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\Policies\Microsoft\Windows NT\Printers(|\\.*)

  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\Printers(|\\.*)

  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\Policies\Microsoft\Windows NT\Rpc(|\\.*)

  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\Rpc(|\\.*)

  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\Policies\Microsoft\Windows\DriverSearching(|\\.*)

  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\DriverSearching(|\\.*)

  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\Policies\Microsoft\Windows\Group Policy(|\\.*)

  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Group Policy(|\\.*)

  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\Policies\Microsoft\Windows\Installer(|\\.*)

  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Installer(|\\.*)

  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\Policies\Microsoft\Windows\Internet Connection Wizard(|\\.*)

  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Internet Connection Wizard(|\\.*)

  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\Policies\Microsoft\Windows\Network Connections(|\\.*)

  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Network Connections(|\\.*)

  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\Policies\Microsoft\Windows\Registration Wizard Control(|\\.*)

  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Registration Wizard Control(|\\.*)

  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\Policies\Microsoft\Peernet(|\\.*)

  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Peernet(|\\.*)

  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\Policies\Microsoft\WindowsFirewall\StandardProfile\IcmpSettings(|\\.*)

  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile\IcmpSettings(|\\.*)

  • HKEY_LOCAL_MACHINE\System\Clone(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\Control\SessionManager(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\SOFTWARE\WOW6432NODE\Microsoft\Windows NT\CurrentVersion\WinLogon(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WinLogon(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\CrashControl(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CrashControl(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\CrashControl(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FileSystem(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\FileSystem(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\FileSystem(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\LSA(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\LSA(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Print\Providers\LanMan Print Services\Servers(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Providers\LanMan Print Services\Servers(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Print\Providers\LanMan Print Services\Servers(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\ProductOptions(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\ProductOptions(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\ProductOptions(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurePipeServers\WinReg(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SecurePipeServers\WinReg(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\SecurePipeServers\WinReg(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\kernel(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager\kernel(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Session Manager\kernel(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Security(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\WMI\Security(|\\.*)

  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\WMI\Security(|\\.*)
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum(|\\.*)
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum(|\\.*)
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum(|\\.*)
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Hardware Profiles(|\\.*)
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Hardware Profiles(|\\.*)
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Hardware Profiles(|\\.*)
  • HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer(|\\.*)
  • HKEY_USERS\.Default\Software\Microsoft\NetDDE(|\\.*)
  • HKEY_USERS\.Default\Software\Microsoft\SystemCertificates\Root\ProtectedRoots(|\\.*)
RegistryStartupAutorun
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\Microsoft\Windows NT\CurrentVersion\IniFileMapping(|\\.*)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping(|\\.*)
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\Microsoft\Windows\CurrentVersion\Run(|\\.*)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run(|\\.*)
RegistryUSBDevices
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\USBSTOR(|\\.*)
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\USBSTOR(|\\.*)
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\USBSTOR(|\\.*)
RegistryWindowsFirewall
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\Policies\Microsoft\WindowsFirewall\DomainProfile(|\\.*)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile(|\\.*)
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\Policies\Microsoft\WindowsFirewall\StandardProfile(|\\.*)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile(|\\.*)
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\Policies\Microsoft\cryptography(|\\.*)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\cryptography(|\\.*)
  • HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\Policies\Microsoft\windows\safer\codeidentifiers(|\\.*)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\windows\safer\codeidentifiers(|\\.*)
Go Up