PS-Remote Get Registry

This playbook leverages the Windows built-in PowerShell and WinRM capabilities to connect to a Windows host to acquire and export the registry as forensic evidence for further analysis. The capture can be for the entire registry or for a specific hive or path.

Pack
WindowsForensics
Tasks
12

Inputs

Outputs

Commands used