Query Typed Urls from the Registry

AID2112302023.YAML

#####aid_begin
#description: fetch the information from typedurls
#id: aid2112302023
#processtype: query
#category: registry
#sourcelink: <na>
#tacticidlist: <na>
#techniqueidlist: <na>
#compatibleos: |-
#  windows 7
#  windows 8.*
#  windows 10
#  windows 11
#  windows server 2008 r2
#  windows server 2012
#  windows server 2012 r2
#  windows server 2016
#  windows server 2019
#compatibleengine: |-
#  powershell 2
#  powershell 3
#  powershell 4
#  powershell 5.*
#  powershell 7.*
#bgcommandlist: |-
#  get-bgregistry
#notes: |-
#  this key contains a listing of 25 recent urls (or file path) that is typed in the internet explorer (ie) or windows explorer address bar. it shows websites suspect has recently been surfing. however, the key will only show links that are fully typed, automatically completed while typing, or links that are selected from the list of stored urls in ie address bar. websites that are accessed via ie favorites are not recorded. ie will only write all the typed urls during that session to the key when ie is closed (accessdata, 2005a). if suspect clears the url history using clear history via ie internet options menu, this key will be completely removed.        
#####aid_end
commands:
- Get-BGRegistry -StartKey "HKCU\Software\Microsoft\Internet Explorer\TypedURLs"

Last updated