User Profile
Data Type: user_profile
Python Parser: RegUserProfile
Python Parser: RegUserProfile
Description
Each row describes a Windows user profile, with account name, SID, profile path, administrative or hidden status, profile state, key time, and registry permissions. Use it to map artifacts to users and identify unusual, orphaned, or concealed profiles. Profile presence does not prove an active session, while absence from this snapshot does not exclude a removed profile.
Timeline
| Timeline Field | Data Field |
|---|---|
| Related User | user_sid |
| Description | path |
| Additional Description | is_admin |
user_name |
Fields
| Output Name | Data Type | Description |
|---|---|---|
user_name |
String | account name derived from the profile directory |
user_sid |
String | security identifier (SID) of the user profile |
path |
String | filesystem path to the user’s profile directory |
is_hidden |
Bool | True if the account is listed as hidden in SpecialAccounts\UserList |
is_admin |
Bool | True if the profile’s State flag indicates administrative rights (0x100 set) |
ref_count |
String | reference count value for the profile entry |
state |
String | raw State field value from the registry (used to infer admin status) |
key_path |
String | full registry key name |
key_modif_time |
DateTime | last modification timestamp of the registry key |
key_security |
Object | |
key_security.owner_sid |
String | SID of the user that owns the registry key |
key_security.group_sid |
String | SID of the group that owns the registry key |
key_security.control_flags[] |
Array[String] | security descriptor control flags for the key |
key_security.sacl_aces[] |
Array[Object] | |
key_security.sacl_aces[].ace_type |
String | type of ACE (e.g., allow, deny) |
key_security.sacl_aces[].ace_flags[] |
Array[String] | ACE flags that modify inheritance or behavior |
key_security.sacl_aces[].rights[] |
Array[String] | permissions granted or denied by the ACE |
key_security.sacl_aces[].account_sid |
String | SID of the account the ACE applies to |
key_security.sacl_aces[].ace_size |
Int | declared ACE size in bytes |
key_security.sacl_aces[].object_type_guid |
String | GUID identifying the object type governed by the ACE |
key_security.sacl_aces[].inherited_object_type_guid |
String | GUID identifying the inherited object type governed by the ACE |
key_security.sacl_aces[].raw_hex |
String | raw ACE bytes preserved as hexadecimal |
key_security.dacl_aces[] |
Array[Object] | |
key_security.dacl_aces[].ace_type |
String | type of ACE (e.g., allow, deny) |
key_security.dacl_aces[].ace_flags[] |
Array[String] | ACE flags that modify inheritance or behavior |
key_security.dacl_aces[].rights[] |
Array[String] | permissions granted or denied by the ACE |
key_security.dacl_aces[].account_sid |
String | SID of the account the ACE applies to |
key_security.dacl_aces[].ace_size |
Int | declared ACE size in bytes |
key_security.dacl_aces[].object_type_guid |
String | GUID identifying the object type governed by the ACE |
key_security.dacl_aces[].inherited_object_type_guid |
String | GUID identifying the inherited object type governed by the ACE |
key_security.dacl_aces[].raw_hex |
String | raw ACE bytes preserved as hexadecimal |