Skip to content

Run Mru

Data Type: run_mru
Python Parser: RegRunMru

Description

Extracts entries from the RunMRU in the NTUser hive, which stores commands typed in the Windows + R dialog.

  • Captures every command a user manually launched via the Run dialog.
  • Preserves the alphabetical index indicating the order of entry.

Timeline

Timeline Field Data Field
Related User key_security.owner_sid
Description executable
Additional Description index

Fields

Output Name Data Type Qualifier Description
executable String COMMAND_LINE command line entered in the Windows + R Run dialog
index String alphabetical index (a‑z) indicating the entry’s position in the RunMRU list
key_path String KEY_PATH full registry key name
key_modif_time DateTime DATE_MODIFICATION last modification timestamp of the registry key
key_security Object
key_security.owner_sid String USER_SID SID of the user that owns the registry key
key_security.group_sid String SID of the group that owns the registry key
key_security.control_flags[] Array[String] security descriptor control flags for the key
key_security.dacl_ace Object
key_security.dacl_ace.ace_type String type of ACE (e.g., allow, deny)
key_security.dacl_ace.account_sid String SID of the account the ACE applies to
key_security.dacl_ace.ace_flags[] Array[String] ACE flags that modify inheritance or behavior
key_security.dacl_ace.rights[] Array[String] permissions granted or denied by the ACE