Skip to content

User Profile

Data Type: user_profile
Python Parser: RegUserProfile

Description

Each row describes a Windows user profile, with account name, SID, profile path, administrative or hidden status, profile state, key time, and registry permissions. Use it to map artifacts to users and identify unusual, orphaned, or concealed profiles. Profile presence does not prove an active session, while absence from this snapshot does not exclude a removed profile.

Timeline

Timeline Field Data Field
Related User user_sid
Description path
Additional Description is_admin
user_name

Fields

Output Name Data Type Description
user_name String account name derived from the profile directory
user_sid String security identifier (SID) of the user profile
path String filesystem path to the user’s profile directory
is_hidden Bool True if the account is listed as hidden in SpecialAccounts\UserList
is_admin Bool True if the profile’s State flag indicates administrative rights (0x100 set)
ref_count String reference count value for the profile entry
state String raw State field value from the registry (used to infer admin status)
key_path String full registry key name
key_modif_time DateTime last modification timestamp of the registry key
key_security Object
key_security.owner_sid String SID of the user that owns the registry key
key_security.group_sid String SID of the group that owns the registry key
key_security.control_flags[] Array[String] security descriptor control flags for the key
key_security.sacl_aces[] Array[Object]
key_security.sacl_aces[].ace_type String type of ACE (e.g., allow, deny)
key_security.sacl_aces[].ace_flags[] Array[String] ACE flags that modify inheritance or behavior
key_security.sacl_aces[].rights[] Array[String] permissions granted or denied by the ACE
key_security.sacl_aces[].account_sid String SID of the account the ACE applies to
key_security.sacl_aces[].ace_size Int declared ACE size in bytes
key_security.sacl_aces[].object_type_guid String GUID identifying the object type governed by the ACE
key_security.sacl_aces[].inherited_object_type_guid String GUID identifying the inherited object type governed by the ACE
key_security.sacl_aces[].raw_hex String raw ACE bytes preserved as hexadecimal
key_security.dacl_aces[] Array[Object]
key_security.dacl_aces[].ace_type String type of ACE (e.g., allow, deny)
key_security.dacl_aces[].ace_flags[] Array[String] ACE flags that modify inheritance or behavior
key_security.dacl_aces[].rights[] Array[String] permissions granted or denied by the ACE
key_security.dacl_aces[].account_sid String SID of the account the ACE applies to
key_security.dacl_aces[].ace_size Int declared ACE size in bytes
key_security.dacl_aces[].object_type_guid String GUID identifying the object type governed by the ACE
key_security.dacl_aces[].inherited_object_type_guid String GUID identifying the inherited object type governed by the ACE
key_security.dacl_aces[].raw_hex String raw ACE bytes preserved as hexadecimal