Built off the open source project Osquery
Description: Values in Windows Registry Hives
What The Data Shows: could determine what registry values exist, this can be used to find installed software, or indicators of compromise; where registry could be used for persistence
SELECT key,path,name,data FROM (`registry`);
@coreymaygard While this query works, it is too broad to be effective. You can some examples in the Query Exchange and the Recommended Queries in CB Live Query where we look for misconfigurations, persistence, and vulnerabilities.