Query Information from the Registry on Recentdocs, Recentapps

AID2112301441.YAML

#####aid_begin
#description: fetch the information from the recentdocs, recentapps
#id: aid2112301441
#processtype: query
#category: registry
#sourcelink: <na>
#tacticidlist: <na>
#techniqueidlist: <na>
#compatibleos: |-
#  windows 7
#  windows 8.*
#  windows 10
#  windows 11
#  windows server 2008 r2
#  windows server 2012
#  windows server 2012 r2
#  windows server 2016
#  windows server 2019
#compatibleengine: |-
#  powershell 2
#  powershell 3
#  powershell 4
#  powershell 5.*
#  powershell 7.*
#bgcommandlist: |-
#  get-bgregistry
#notes: |-
#  this registry key maintains a list of the files and apps that the currently logged on user accessed or executed via windows explorer and corresponds to the file listing. this key corresponds to %userprofile%\recent (my recent documents). the key contains local or network files that are recently opened and only the filename in binary form is stored.
#####aid_end
commands:
- Get-BGRegistry -StartKey "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs"
- Get-BGRegistry -StartKey "HKCU\Software\Microsoft\Windows\CurrentVersion\Search\RecentApps"

Last updated