Skip to content

Reg Autoruns

Data Type: reg_autoruns
Python Parser: RegAutorunsUser

Description

Extracts persistence‑related registry data from the USER hive (HKCU).

  • Enumerates well‑known keys that Windows and third‑party software use for automatic execution (autoruns) in the current user hive.
  • Groups the results by a persistence type (e.g. “Startup Run”, “Shell Load and Run”) and returns the values found under each key.

Timeline

Timeline Field Data Field
Related User key_security.owner_sid
Description type
key_path
Additional Description values

Fields

Output Name Data Type Qualifier Description
type String Logical name of the persistence mechanism (e.g., ‘Startup Run’)
values Object Value set extracted from the registry key.
key_path String KEY_PATH full registry key name
key_modif_time DateTime DATE_MODIFICATION last modification timestamp of the registry key
key_security Object
key_security.owner_sid String USER_SID SID of the user that owns the registry key
key_security.group_sid String SID of the group that owns the registry key
key_security.control_flags[] Array[String] security descriptor control flags for the key
key_security.dacl_ace Object
key_security.dacl_ace.ace_type String type of ACE (e.g., allow, deny)
key_security.dacl_ace.account_sid String SID of the account the ACE applies to
key_security.dacl_ace.ace_flags[] Array[String] ACE flags that modify inheritance or behavior
key_security.dacl_ace.rights[] Array[String] permissions granted or denied by the ACE