Registry
Walks registry hives as a key tree, reading the loaded hives exactly as they were collected.
Where the Artifacts screen hands you a tidied result - "the autorun entries" - this is where you can see which key that result came from. It is also where you go for keys no extraction rule covers.
Walking the tree
The tree expands project → host → hive → key. The number beside a key is how many values sit beneath it. Click a key and its values appear in the grid.
Search scope in the filter bar decides whether the keyword is matched against key names, value names or value contents.
The hex viewer for binary values
A row whose type is BINARY shows its value cell as a link, and clicking it opens the hex viewer: offsets down the left, sixteen bytes of hex across, and the ASCII beside them.
- Drag across the bytes to select a range. Hex and ASCII highlight the same span
- The selection is decoded as a string or BASE64 and shown underneath
- Pick the charset from UTF-8, UTF-16LE, UTF-16BE, EUC-KR
- Copy puts the selected bytes on the clipboard as a hex string
The registry routinely buries paths and command lines inside binary values as UTF-16. This is how you read an autorun entry or a shellbag whose value tells you nothing as it stands.
How you investigate here
Results are handled the same way the Artifacts screen handles them. Right-click a cell to filter
on its value, watch the conditions stack up in the chip bar as the query they stand for
(Ctrl+Q clears them), star a record to tag it and leave a note, and click a row for the detail
panel with every field and tag on it. There is more in
Artifacts.
The filter bar is shared with the other browsing screens, so settling on a host and a time range once lets you carry that scope from screen to screen.
Next: Logs.