System Info
Last updated
Last updated
HKLM\SYSTEM\CurrentControlSet\Control\ComputerName
Different ControlSet version could indicate past hostnames.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion
HKLM\SYSTEM\Setup\Source OS
HKLM\SYSTEM\<CurrentControlSet>\Control\TimeZoneInformation
Track network interfaces in use and their last settings. Shows both physical and virtual interfaces:
HKLM\SYSTEM\<CurrentControlSet>\Services\Tcpip\Parameters\Interfaces
Track human readable names of network card GUIDs found in interfaces (physical cards only):
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkCards
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\Signatures\Managed (part of AD Domain)
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\Signatures\Unmanaged (outside of AD Domain)
Use ProfileGUID in previous key ^ to find first and last time connected to network (timezone stored in 128-bit systemtime - local time):
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\Profiles
Audit usage of microphone, webcam, location, and other application specific settings.(windows 64-bit filetime format)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\ConsentStore
NTUSER\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\ConsentStore
Nonpackaged = Non-Microsoft Apps
When a system shutdown (64-bit filetime):
HKML\SYSTEM\<CurrentControlSet>\Control\Windows