Environment
Objective
How to search for the following registry entries within EDR Process Search page;
- HKEY_CLASSES_ROOT
- HKEY_CURRENT_USER
- HKEY_LOCAL_MACHINE
- HKEY_USERS
- HKEY_CURRENT_CONFIG
Resolution
- Log into the EDR console
- Navigate to the 'Process Search' page
- Use the search term regmod: followed by the registry key path to search for as documented below.
regmod:registry\machine\software\classes\*
regmod:registry\user\<SID OF USER>\*
regmod:registry\machine\*
regmod:registry\user\*
regmod:registry\machine\system\*
Related Content