frida_win_registry_monitor
Monitor Windows registry operations in a target process by hooking advapi32.dll functions. Logs key paths, value names, and data sizes.
Instructions
[Windows] Monitor Registry operations in a target process.
Hooks RegOpenKeyExW, RegSetValueExW, RegQueryValueExW, RegDeleteKeyW in advapi32.dll. Logs key paths, value names, and data sizes.
target: process name or pid (string).
duration_seconds: how long to monitor (default 10).
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| target | Yes | ||
| duration_seconds | No |