registry_get_persistence
Extract Windows persistence mechanisms like Run keys and services from registry hives to identify potential malware or unauthorized startup entries during forensic investigations.
Instructions
Get persistence mechanisms (Run keys, services) from registry.
Input Schema
TableJSON Schema
| Name | Required | Description | Default |
|---|---|---|---|
| software_hive | No | ||
| system_hive | No | ||
| ntuser_hive | No | ||
| include_microsoft_services | No |