I had the default registry monitoring turned on for our desktops for a day but it used way too much of our license so I had to disable it.
I am interested in monitoring a few keys but I am unclear on how to fill out the hive portion within the inputs.conf file.
Example of the keys I might monitor:
Here are a few examples that I run. For HKCU, you have to use this format:
[WinRegMon://hkcu_run1]
disabled = 0
hive = \\REGISTRY\\USER\\.*\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\Run\\.*
proc = .*
type = set|create|delete|rename
index = windows
For HKLM you use MACHINE:
[WinRegMon://hklm_run1]
disabled = 0
hive = \\REGISTRY\\MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\Run\\.*
proc = .*
type = set|create|delete|rename
index = windows
You don't need to add stanzas for HKU, because your HKCU stanzas will suffice.
Hi,
Can you advise how you can monitor multiple Reg Keys in the same stanza ?
Thank you