PS-Remote Get Registry
This playbook leverages the Windows built-in PowerShell and WinRM capabilities to connect to a Windows host to acquire and export the registry as forensic evidence for further analysis. The capture can be for the entire registry or for a specific hive or path.
- Pack
- WindowsForensics
- Tasks
- 12
Inputs
- Host — A single hostname or IP address from which to export the registry file. For example, testpc01.
- RegistryHive — The registry hive/path to export. If no value is specified, the entire registry will be exported.
- FilePath — The path on the hostname on which to create the registry file. The default path will be c:\registry.reg. If the AddHostNameToFile input is "true", the file downloaded to XSOAR will contain the hostname.
- ZipRegistry — Specify "true" to zip the reg file before sending it to XSOAR.
- AddHostNameToFile — Specify "true" for the downloaded filename to contain the hostname, or "false" to keep the filename as configured in the FilePath argument.
Outputs
- RegistryDetails — The Registry file details.
Commands used
- ps-remote-download-file
- ps-remote-export-registry
- setEntriesTags