Following is the list of data that is collected from Windows Agent 5.1.30 and above for Forensics data collection:
hklm\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
hklm\SOFTWARE\Classes\Protocols\Filter
hklm\SOFTWARE\Classes\Protocols\Handler
hklm\Software\Classes*\ShellEx\ContextMenuHandlers
hklm\Software\Classes\Drive\ShellEx\ContextMenuHandlers
hklm\Software\Classes*\ShellEx\PropertySheetHandlers
hklm\Software\Classes\Directory\ShellEx\ContextMenuHandlers
hklm\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers
hklm\Software\Classes\Folder\ShellEx\ContextMenuHandler
hklm\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
hklm\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
hklm\Software\Microsoft\Internet Explorer\Extensions
hklm\Software\Wow6432Node\Microsoft\Internet Explorer\Extensions
hklm\Software\Google\Chrome\Extensions
hklm\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
hklm\System\CurrentControlSet\Services
hklm\Software\Microsoft\Windows NT\CurrentVersion\Drivers32
hklm\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32
hklm\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall
hklm\Software\Microsoft\Windows\CurrentVersion\Uninstall
Was this topic helpful?