daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

recmd.md (28694B)


      1 ---
      2 title: "RECmd Registry Forensics"
      3 description: "RECmd registry analysis workflow: batch files, keys of interest and evidence extraction."
      4 category: dfir
      5 tags: [dfir, registry, windows]
      6 tools: [RECmd, Registry Explorer]
      7 difficulty: advanced
      8 updated: "2026-08-09"
      9 source: "vault:DFIR/REDmd - Quick Cheat sheet.md"
     10 ---
     11 
     12 # RECmd Registry Forensics
     13 
     14 ## Part 1: Quick Reference Cheat Sheet
     15 
     16 ### Essential Command Templates
     17 
     18 ```powershell
     19 # UPDATE BATCH FILES
     20 RECmd.exe --sync
     21 
     22 # PARSE SINGLE HIVE
     23 RECmd.exe -f <HIVE_PATH> --csv <OUT_DIR> --csvf <FILENAME>.csv --dt "dd/MM/yyyy HH:mm:ss"
     24 
     25 # PARSE ALL HIVES IN DIRECTORY
     26 RECmd.exe -d <HIVES_DIR> --csv <OUT_DIR> --dt "dd/MM/yyyy HH:mm:ss"
     27 
     28 # RUN BATCH FILE (TRIAGE)
     29 RECmd.exe -d <HIVES_DIR> --bn BatchExamples\DFIRBatch.reb --csv <OUT_DIR> --csvf Triage.csv --dt "dd/MM/yyyy HH:mm:ss"
     30 
     31 # EXTRACT SPECIFIC KEY
     32 RECmd.exe -f <HIVE_PATH> --kn "KeyPath\Here" --csv <OUT_DIR> --csvf Output.csv
     33 
     34 # SEARCH FOR KEYWORD
     35 RECmd.exe -f <HIVE_PATH> --sd "keyword" --csv <OUT_DIR> --csvf Search.csv
     36 
     37 # RECOVER DELETED KEYS/VALUES (DEFAULT = ON)
     38 RECmd.exe -f <HIVE_PATH> --recover true --csv <OUT_DIR> --csvf Recovered.csv
     39 
     40 # REPLAY TRANSACTION LOGS (DEFAULT = ON)
     41 RECmd.exe -f <HIVE_PATH> --nl false --csv <OUT_DIR> --csvf Clean.csv
     42 ```
     43 
     44 ---
     45 
     46 ### Critical Flags Reference
     47 
     48 | Flag | Purpose | Example |
     49 |------|---------|---------|
     50 | `-f` | Single hive file | `-f C:\Evidence\SYSTEM` |
     51 | `-d` | Directory (recursive) | `-d C:\Evidence\Hives` |
     52 | `--bn` | Batch file | `--bn BatchExamples\DFIRBatch.reb` |
     53 | `--csv` | Output directory | `--csv C:\Output\CSV` |
     54 | `--csvf` | Override CSV filename | `--csvf SYSTEM_results.csv` |
     55 | `--dt` | Date format (UK) | `--dt "dd/MM/yyyy HH:mm:ss"` |
     56 | `--nl` | Ignore transaction logs | `--nl false` (default = replay logs) |
     57 | `--recover` | Recover deleted data | `--recover true` (default = on) |
     58 | `--kn` | Extract specific key | `--kn "ControlSet001\Services"` |
     59 | `--vn` | Extract specific value | `--vn "ProductName"` |
     60 | `--sa` | Search all | `--sa "malware.exe"` |
     61 | `--sk` | Search key names | `--sk "Run"` |
     62 | `--sv` | Search value names | `--sv "Path"` |
     63 | `--sd` | Search value data | `--sd "C:\Windows"` |
     64 | `--regex` | Enable regex search | `--regex --sd ".*\.exe$"` |
     65 | `--vss` | Parse Volume Shadow Copies | `--vss` |
     66 | `--q` | Quiet mode | `--q` |
     67 
     68 ---
     69 
     70 ### Batch Files Quick Reference
     71 
     72 | Batch File | Purpose | Command |
     73 |-----------|---------|---------|
     74 | `DFIRBatch.reb` | Full triage (System Info, Execution, Persistence, User Activity) | `--bn BatchExamples\DFIRBatch.reb` |
     75 | `RegistryASEPs.reb` | Persistence detection (~500 keys, ~400 values) | `--bn BatchExamples\RegistryASEPs.reb` |
     76 | Custom `.reb` | Targeted extraction (USB, Run keys, etc.) | Create your own (see Part 6) |
     77 
     78 ---
     79 
     80 ### File Structure
     81 
     82 ```text
     83 <CASE_DIR>/
     84 ├── Tools/
     85 │   └── RECmd/
     86 │       ├── RECmd.exe
     87 │       ├── RLA.exe                 # Transaction log replayer
     88 │       └── BatchExamples/
     89 │           ├── DFIRBatch.reb
     90 │           └── RegistryASEPs.reb
     91 ├── Evidence/
     92 │   └── Hives/
     93 │       ├── SAM
     94 │       ├── SECURITY
     95 │       ├── SOFTWARE
     96 │       ├── SYSTEM
     97 │       ├── SYSTEM.LOG1            # Transaction logs
     98 │       ├── SYSTEM.LOG2
     99 │       └── NTUSER.DAT
    100 └── Output/
    101     └── CSV/
    102 ```
    103 
    104 ---
    105 
    106 ## Part 2: Workflow for Your Hive Set
    107 
    108 ### Setup (One-Time)
    109 
    110 ```powershell
    111 # 1. Create folder structure
    112 mkdir C:\Cases\MyCase\Tools\RECmd
    113 mkdir C:\Cases\MyCase\Evidence\Hives
    114 mkdir C:\Cases\MyCase\Output\CSV
    115 
    116 # 2. Download RECmd to Tools\RECmd folder
    117 # Source: https://ericzimmerman.github.io/#!index.md
    118 
    119 # 3. Copy your hives to Evidence\Hives:
    120 #    - SAM
    121 #    - SECURITY
    122 #    - SOFTWARE
    123 #    - SYSTEM (+ SYSTEM.LOG1, SYSTEM.LOG2 if available)
    124 #    - NTUSER.DAT
    125 
    126 # 4. Update batch files
    127 cd C:\Cases\MyCase\Tools\RECmd
    128 RECmd.exe --sync
    129 ```
    130 
    131 ---
    132 
    133 ### Workflow 1: Fast Triage (5 minutes)
    134 
    135 **Objective:** Get high-value artefacts immediately.
    136 
    137 ```powershell
    138 cd C:\Cases\MyCase\Tools\RECmd
    139 
    140 # Run DFIRBatch against all hives
    141 RECmd.exe -d C:\Cases\MyCase\Evidence\Hives --bn BatchExamples\DFIRBatch.reb --csv C:\Cases\MyCase\Output\CSV --csvf Triage.csv --q --dt "dd/MM/yyyy HH:mm:ss"
    142 ```
    143 
    144 **Output:** Single CSV file `Triage.csv` containing:
    145 - System info (OS version, hostname, timezone)
    146 - User accounts (SAM)
    147 - Program execution (ShimCache, BAM/DAM, UserAssist)
    148 - Persistence (Run keys, services, scheduled tasks)
    149 - USB devices (USBSTOR, mounted devices)
    150 - User activity (RecentDocs, TypedPaths, searches)
    151 
    152 **Review in Timeline Explorer:**
    153 1. Open `C:\Cases\MyCase\Output\CSV\Triage.csv`
    154 2. Filter by `Category` column: `Program Execution`, `Persistence`, `User Activity`, `Devices`
    155 
    156 ---
    157 
    158 ### Workflow 2: Hive-by-Hive Deep Dive
    159 
    160 #### SAM Hive: User Accounts
    161 
    162 **What you'll find:** Local user accounts (username, RID, SID), last login times, logon counts, password policies, group membership.
    163 
    164 ```powershell
    165 RECmd.exe -f C:\Cases\MyCase\Evidence\Hives\SAM --csv C:\Cases\MyCase\Output\CSV --csvf SAM.csv --dt "dd/MM/yyyy HH:mm:ss"
    166 ```
    167 
    168 **Key artefacts to review:**
    169 
    170 | KeyPath | What to look for |
    171 |---------|------------------|
    172 | `SAM\Domains\Account\Users\000001F4` | RID 500 = Built-in Administrator account |
    173 | `SAM\Domains\Account\Users\<RID>` | Check `LastWriteTime` = account creation/modification |
    174 | Value: `F` | Account metadata (flags, lockout) |
    175 | Value: `V` | Username |
    176 
    177 **Red flags:**
    178 - New local admin accounts (RID 500 group membership)
    179 - Accounts with zero logon count but recent `LastWriteTime` (re-enabled?)
    180 - Disabled accounts with activity timestamps
    181 
    182 ---
    183 
    184 #### SECURITY Hive: Audit Configuration
    185 
    186 **What you'll find:** Security policies, audit settings, LSA secrets (structure only; data encrypted).
    187 
    188 ```powershell
    189 RECmd.exe -f C:\Cases\MyCase\Evidence\Hives\SECURITY --csv C:\Cases\MyCase\Output\CSV --csvf SECURITY.csv --dt "dd/MM/yyyy HH:mm:ss"
    190 ```
    191 
    192 **Key artefacts:**
    193 
    194 | KeyPath | What to look for |
    195 |---------|------------------|
    196 | `Policy\PolAdtEv` | Audit policy bitmask (disabled = evasion) |
    197 | `Policy\Secrets` | LSA secrets structure (data encrypted) |
    198 
    199 > **Note —** Limited forensic value for offline analysis; most data encrypted.
    200 
    201 ---
    202 
    203 #### SOFTWARE Hive: System Configuration & Persistence
    204 
    205 **What you'll find:** OS version, hostname, install date, installed software, persistence mechanisms (Run keys, scheduled tasks), user profile paths (ProfileList), network shares (MountPoints2).
    206 
    207 ```powershell
    208 RECmd.exe -f C:\Cases\MyCase\Evidence\Hives\SOFTWARE --bn BatchExamples\DFIRBatch.reb --csv C:\Cases\MyCase\Output\CSV --csvf SOFTWARE.csv --dt "dd/MM/yyyy HH:mm:ss"
    209 ```
    210 
    211 **Key artefacts to review:**
    212 
    213 | KeyPath | What to look for |
    214 |---------|------------------|
    215 | `Microsoft\Windows NT\CurrentVersion` | `ProductName`, `ReleaseId`, `InstallDate` |
    216 | `Microsoft\Windows\CurrentVersion\Run` | Machine-wide auto-start entries |
    217 | `Microsoft\Windows\CurrentVersion\RunOnce` | One-time execution entries |
    218 | `Wow6432Node\Microsoft\Windows\CurrentVersion\Run` | 32-bit persistence on 64-bit systems |
    219 | `Microsoft\Windows NT\CurrentVersion\ProfileList` | User SIDs → Profile paths (e.g., `C:\Users\JohnDoe`) |
    220 | `Microsoft\Windows\CurrentVersion\Uninstall` | Installed software (`DisplayName`, `InstallDate`) |
    221 | `Microsoft\Windows\CurrentVersion\Explorer\MountPoints2` | Mapped drives, UNC shares |
    222 
    223 **Persistence hunt:**
    224 
    225 ```powershell
    226 # Extract all Run keys
    227 RECmd.exe -f C:\Cases\MyCase\Evidence\Hives\SOFTWARE --kn "Microsoft\Windows\CurrentVersion\Run" --csv C:\Cases\MyCase\Output\CSV --csvf Run_keys.csv --dt "dd/MM/yyyy HH:mm:ss"
    228 
    229 # Search for suspect paths
    230 RECmd.exe -f C:\Cases\MyCase\Evidence\Hives\SOFTWARE --sd "AppData\Roaming" --csv C:\Cases\MyCase\Output\CSV --csvf Suspect_paths.csv
    231 ```
    232 
    233 **Red flags:**
    234 - Obfuscated Run key values (Base64, PowerShell encoded commands)
    235 - Non-standard paths (`C:\Temp`, `C:\ProgramData`, user AppData)
    236 - Recently modified Run keys (check `LastWriteTime`)
    237 
    238 ---
    239 
    240 #### SYSTEM Hive: Hardware, Services, USB Devices, Execution
    241 
    242 **What you'll find:** Services, USB device history (USBSTOR, mounted devices), ShimCache (file existence, NOT execution proof), BAM/DAM (execution evidence with timestamps), network configuration, timezone.
    243 
    244 ```powershell
    245 RECmd.exe -f C:\Cases\MyCase\Evidence\Hives\SYSTEM --bn BatchExamples\DFIRBatch.reb --csv C:\Cases\MyCase\Output\CSV --csvf SYSTEM.csv --dt "dd/MM/yyyy HH:mm:ss"
    246 ```
    247 
    248 **Key artefacts to review:**
    249 
    250 | KeyPath | What to look for |
    251 |---------|------------------|
    252 | `ControlSet001\Enum\USBSTOR` | USB storage devices (VID, PID, serial number) |
    253 | `ControlSet001\Enum\USB` | All USB devices (including non-storage) |
    254 | `MountedDevices` | Drive letters → Device serial numbers |
    255 | `ControlSet001\Services` | Service binaries (check `ImagePath`, `Start` type) |
    256 | `ControlSet001\Control\Session Manager\AppCompatCache` | ShimCache: file paths, modified times, sizes |
    257 | `ControlSet001\Services\bam\State\UserSettings\<SID>` | BAM: execution timestamps (Win10 1709+) |
    258 | `ControlSet001\Services\dam\State\UserSettings\<SID>` | DAM: Desktop Activity Moderator |
    259 | `ControlSet001\Control\TimeZoneInformation` | Timezone, DST settings |
    260 | `Select` | `Current` = active ControlSet number |
    261 
    262 **USB device extraction:**
    263 
    264 ```powershell
    265 # Extract USB storage devices
    266 RECmd.exe -f C:\Cases\MyCase\Evidence\Hives\SYSTEM --kn "ControlSet001\Enum\USBSTOR" --csv C:\Cases\MyCase\Output\CSV --csvf USB_STOR.csv
    267 
    268 # Extract all USB devices
    269 RECmd.exe -f C:\Cases\MyCase\Evidence\Hives\SYSTEM --kn "ControlSet001\Enum\USB" --csv C:\Cases\MyCase\Output\CSV --csvf USB_all.csv
    270 
    271 # Extract mounted devices
    272 RECmd.exe -f C:\Cases\MyCase\Evidence\Hives\SYSTEM --kn "MountedDevices" --csv C:\Cases\MyCase\Output\CSV --csvf Mounted.csv
    273 ```
    274 
    275 **Execution evidence (BAM/DAM):**
    276 
    277 ```powershell
    278 # Extract BAM (Win10 1709+)
    279 RECmd.exe -f C:\Cases\MyCase\Evidence\Hives\SYSTEM --kn "ControlSet001\Services\bam\State\UserSettings" --csv C:\Cases\MyCase\Output\CSV --csvf BAM.csv --dt "dd/MM/yyyy HH:mm:ss"
    280 
    281 # Extract DAM
    282 RECmd.exe -f C:\Cases\MyCase\Evidence\Hives\SYSTEM --kn "ControlSet001\Services\dam\State\UserSettings" --csv C:\Cases\MyCase\Output\CSV --csvf DAM.csv --dt "dd/MM/yyyy HH:mm:ss"
    283 ```
    284 
    285 **Review BAM/DAM output:**
    286 - Each subkey = User SID (cross-reference with SOFTWARE\ProfileList)
    287 - Value names = Hex timestamps
    288 - Value data = Executable full path
    289 - **This is STRONG execution evidence**
    290 
    291 **ShimCache extraction:**
    292 
    293 ```powershell
    294 RECmd.exe -f C:\Cases\MyCase\Evidence\Hives\SYSTEM --kn "ControlSet001\Control\Session Manager\AppCompatCache" --csv C:\Cases\MyCase\Output\CSV --csvf ShimCache.csv --dt "dd/MM/yyyy HH:mm:ss"
    295 ```
    296 
    297 **ShimCache caveats:**
    298 - **Does NOT prove execution**, only file existence
    299 - `LastModified` = file timestamp, NOT execution time
    300 - Useful for: identifying suspect file paths, confirming file presence (even if deleted)
    301 
    302 **Red flags:**
    303 - Unusual service binaries (non-System32 paths, renamed system tools)
    304 - USB devices connected during incident timeframe (check `LastWriteTime` on USBSTOR keys)
    305 - BAM/DAM entries for known malware paths
    306 - ShimCache entries for staging directories (`C:\Temp`, `C:\Users\Public`)
    307 
    308 ---
    309 
    310 #### NTUSER.DAT Hive: User Activity
    311 
    312 **What you'll find:** Recently opened files (RecentDocs), program execution (UserAssist), folder access history (ShellBags), typed paths, search terms (WordWheelQuery), Office documents with macros enabled (TrustRecords).
    313 
    314 ```powershell
    315 RECmd.exe -f C:\Cases\MyCase\Evidence\Hives\NTUSER.DAT --bn BatchExamples\DFIRBatch.reb --csv C:\Cases\MyCase\Output\CSV --csvf NTUSER.csv --dt "dd/MM/yyyy HH:mm:ss"
    316 ```
    317 
    318 **Key artefacts to review:**
    319 
    320 | KeyPath | What to look for |
    321 |---------|------------------|
    322 | `Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\<GUID>\Count` | GUI program execution (ROT13 encoded) |
    323 | `Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs` | Recently opened files by extension |
    324 | `Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU` | Open/Save dialog history |
    325 | `Software\Microsoft\Windows\Shell\BagMRU` | Folder access history (ShellBags) |
    326 | `Software\Microsoft\Windows\CurrentVersion\Explorer\TypedPaths` | Paths typed into Explorer address bar |
    327 | `Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU` | Commands in Win+R Run dialog |
    328 | `Software\Microsoft\Windows\CurrentVersion\Explorer\WordWheelQuery` | Windows Search queries |
    329 | `Software\Microsoft\Office\<Version>\<App>\Security\Trusted Documents\TrustRecords` | Office files with macros enabled |
    330 
    331 **UserAssist extraction:**
    332 
    333 ```powershell
    334 RECmd.exe -f C:\Cases\MyCase\Evidence\Hives\NTUSER.DAT --kn "Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist" --csv C:\Cases\MyCase\Output\CSV --csvf UserAssist.csv
    335 ```
    336 
    337 **UserAssist decoding:**
    338 - Value names are ROT13 encoded (e.g., `HRZR_PGYFRFFVATF` = `UEME_PGULESSFVATS`)
    339 - Timeline Explorer auto-decodes
    340 - Manual: use an online ROT13 decoder
    341 - Value data contains: execution count, last execution timestamp
    342 
    343 **RecentDocs extraction:**
    344 
    345 ```powershell
    346 RECmd.exe -f C:\Cases\MyCase\Evidence\Hives\NTUSER.DAT --kn "Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs" --csv C:\Cases\MyCase\Output\CSV --csvf RecentDocs.csv
    347 ```
    348 
    349 **ShellBags extraction:**
    350 
    351 ```powershell
    352 RECmd.exe -f C:\Cases\MyCase\Evidence\Hives\NTUSER.DAT --kn "Software\Microsoft\Windows\Shell\BagMRU" --csv C:\Cases\MyCase\Output\CSV --csvf ShellBags.csv
    353 ```
    354 
    355 **Search terms extraction:**
    356 
    357 ```powershell
    358 RECmd.exe -f C:\Cases\MyCase\Evidence\Hives\NTUSER.DAT --kn "Software\Microsoft\Windows\CurrentVersion\Explorer\WordWheelQuery" --csv C:\Cases\MyCase\Output\CSV --csvf Searches.csv
    359 ```
    360 
    361 **Red flags:**
    362 - Searches for anti-forensics tools ("delete logs", "wipe files")
    363 - Execution of tools from USB/external drives (UserAssist)
    364 - Recently opened files with suspect extensions (`.exe`, `.bat`, `.ps1` in RecentDocs)
    365 - Office TrustRecords for phishing document paths (e.g., `Downloads\invoice.docm`)
    366 - TypedPaths/RunMRU containing attacker commands (e.g., `powershell.exe -enc <Base64>`)
    367 
    368 **Multiple NTUSER.DAT files (multi-user system):**
    369 
    370 ```powershell
    371 # 1. Get user list from SOFTWARE hive
    372 RECmd.exe -f C:\Cases\MyCase\Evidence\Hives\SOFTWARE --kn "Microsoft\Windows NT\CurrentVersion\ProfileList" --csv C:\Cases\MyCase\Output\CSV --csvf Users.csv
    373 
    374 # 2. Process each user's NTUSER.DAT (example for JohnDoe)
    375 RECmd.exe -f "C:\Users\JohnDoe\NTUSER.DAT" --bn BatchExamples\DFIRBatch.reb --csv C:\Cases\MyCase\Output\CSV --csvf NTUSER_JohnDoe.csv
    376 
    377 # 3. Repeat for additional users
    378 RECmd.exe -f "C:\Users\JaneSmith\NTUSER.DAT" --bn BatchExamples\DFIRBatch.reb --csv C:\Cases\MyCase\Output\CSV --csvf NTUSER_JaneSmith.csv
    379 ```
    380 
    381 ---
    382 
    383 ### Workflow 3: Persistence Hunting
    384 
    385 **Objective:** Identify all auto-start locations (ASEPs).
    386 
    387 ```powershell
    388 # Run RegistryASEPs batch (Troy Larson)
    389 RECmd.exe -d C:\Cases\MyCase\Evidence\Hives --bn BatchExamples\RegistryASEPs.reb --csv C:\Cases\MyCase\Output\CSV --csvf Persistence.csv --dt "dd/MM/yyyy HH:mm:ss"
    390 ```
    391 
    392 **Output:** ~500 registry keys, ~400 values covering Run/RunOnce keys (machine + user), services, scheduled tasks, Winlogon entries, Image File Execution Options, AppInit_DLLs, browser helper objects (BHOs), startup folder paths.
    393 
    394 **Timeline Explorer review:**
    395 1. Open `Persistence.csv`
    396 2. Filter by `Category` = "Persistence" or "Autoruns"
    397 3. Sort by `LastWriteTime` (most recent first)
    398 4. Focus on: unknown/unsigned binaries, non-standard paths, Base64/encoded commands, timestamps matching incident timeframe
    399 
    400 ---
    401 
    402 ### Workflow 4: Keyword Search Across All Hives
    403 
    404 **Scenario:** Search for specific IOC (e.g., `malware.exe`).
    405 
    406 ```powershell
    407 # Search all value data for keyword
    408 RECmd.exe -d C:\Cases\MyCase\Evidence\Hives --sd "malware.exe" --csv C:\Cases\MyCase\Output\CSV --csvf Search_malware.csv
    409 
    410 # Search with regex (all .exe files in Temp)
    411 RECmd.exe -d C:\Cases\MyCase\Evidence\Hives --regex --sd "C:\\\\Temp\\\\.*\\.exe" --csv C:\Cases\MyCase\Output\CSV --csvf Search_Temp_EXE.csv
    412 
    413 # Search key names
    414 RECmd.exe -d C:\Cases\MyCase\Evidence\Hives --sk "Run" --csv C:\Cases\MyCase\Output\CSV --csvf Search_Run_keys.csv
    415 
    416 # Search value names
    417 RECmd.exe -d C:\Cases\MyCase\Evidence\Hives --sv "ImagePath" --csv C:\Cases\MyCase\Output\CSV --csvf Search_ImagePath.csv
    418 ```
    419 
    420 ---
    421 
    422 ## Part 3: Recovering Deleted Registry Data
    423 
    424 ### Understanding Deleted Data
    425 
    426 Registry deletion behaviour:
    427 - Deleted keys/values are NOT immediately removed from hive file
    428 - Marked as "deleted" in hive structure but data remains until overwritten
    429 - RECmd can recover deleted entries using `--recover` switch (DEFAULT = ON)
    430 
    431 What can be recovered: deleted registry keys, deleted values, slack space (residual data in unused hive blocks).
    432 
    433 ---
    434 
    435 ### Method 1: Automatic Recovery (Default)
    436 
    437 ```powershell
    438 # Recovery is ON by default
    439 RECmd.exe -f C:\Cases\MyCase\Evidence\Hives\SOFTWARE --csv C:\Cases\MyCase\Output\CSV --csvf SOFTWARE_recovered.csv
    440 
    441 # Explicitly enable (same as default)
    442 RECmd.exe -f C:\Cases\MyCase\Evidence\Hives\SOFTWARE --recover true --csv C:\Cases\MyCase\Output\CSV --csvf SOFTWARE_recovered.csv
    443 ```
    444 
    445 Identifying recovered data in CSV output: check `IsDeleted` column (if present in plugin output); deleted keys show in output with timestamps but marked as removed.
    446 
    447 ---
    448 
    449 ### Method 2: Search Slack Space
    450 
    451 Slack space = unused portions of hive file blocks containing residual deleted data.
    452 
    453 ```powershell
    454 # Search slack space for keyword
    455 RECmd.exe -f C:\Cases\MyCase\Evidence\Hives\SOFTWARE --ss --sd "deleted_value" --csv C:\Cases\MyCase\Output\CSV --csvf Slack_search.csv
    456 
    457 # Search all (keys + values + data + slack)
    458 RECmd.exe -f C:\Cases\MyCase\Evidence\Hives\SOFTWARE --sa "keyword" --csv C:\Cases\MyCase\Output\CSV --csvf All_search.csv
    459 ```
    460 
    461 ---
    462 
    463 ### Method 3: Transaction Log Replay (Clean Dirty Hives)
    464 
    465 **Scenario:** Hive is "dirty" (not cleanly shut down) and transaction logs exist.
    466 
    467 Transaction logs: `*.LOG1`, `*.LOG2` files contain uncommitted changes.
    468 
    469 RECmd behaviour:
    470 - `--nl false` (DEFAULT) = replays transaction logs → clean hive data
    471 - `--nl true` = ignores transaction logs → may miss recent data
    472 
    473 **Check for transaction logs:**
    474 
    475 ```powershell
    476 # Example: SYSTEM hive
    477 dir C:\Cases\MyCase\Evidence\Hives\SYSTEM*
    478 # Expected files: SYSTEM, SYSTEM.LOG1, SYSTEM.LOG2
    479 ```
    480 
    481 **Parse with transaction log replay:**
    482 
    483 ```powershell
    484 # Ensure .LOG1 and .LOG2 are in same directory as hive
    485 RECmd.exe -f C:\Cases\MyCase\Evidence\Hives\SYSTEM --nl false --csv C:\Cases\MyCase\Output\CSV --csvf SYSTEM_clean.csv
    486 ```
    487 
    488 **If transaction logs are missing:**
    489 
    490 ```powershell
    491 # Parse without transaction logs (may be incomplete)
    492 RECmd.exe -f C:\Cases\MyCase\Evidence\Hives\SYSTEM --nl true --csv C:\Cases\MyCase\Output\CSV --csvf SYSTEM_dirty.csv
    493 ```
    494 
    495 **Alternative: Use RLA.exe to create clean hive** (RLA.exe = Registry Log Analyser, included with RECmd).
    496 
    497 ```powershell
    498 # Replay transaction logs and output clean hive
    499 cd C:\Cases\MyCase\Tools\RECmd
    500 RLA.exe -f C:\Cases\MyCase\Evidence\Hives\SYSTEM --out C:\Cases\MyCase\Evidence\Hives\Clean
    501 
    502 # Output: C:\Cases\MyCase\Evidence\Hives\Clean\SYSTEM (clean copy)
    503 
    504 # Now parse clean hive with RECmd
    505 RECmd.exe -f C:\Cases\MyCase\Evidence\Hives\Clean\SYSTEM --csv C:\Cases\MyCase\Output\CSV --csvf SYSTEM_clean.csv
    506 
    507 # RLA for entire directory
    508 RLA.exe -d C:\Cases\MyCase\Evidence\Hives --out C:\Cases\MyCase\Evidence\Hives\Clean
    509 ```
    510 
    511 ---
    512 
    513 ### Method 4: Volume Shadow Copy Analysis
    514 
    515 **Scenario:** Recover historical registry states from VSS snapshots. Prerequisite: VSS snapshots must exist on evidence drive.
    516 
    517 ```powershell
    518 # Parse hive + all VSS snapshots
    519 RECmd.exe -f C:\Cases\MyCase\Evidence\Hives\SOFTWARE --vss --csv C:\Cases\MyCase\Output\CSV --csvf SOFTWARE_VSS.csv --dt "dd/MM/yyyy HH:mm:ss"
    520 
    521 # Or entire directory with VSS
    522 RECmd.exe -d C:\Cases\MyCase\Evidence\Hives --vss --csv C:\Cases\MyCase\Output\CSV --csvf All_VSS.csv
    523 ```
    524 
    525 Output: separate entries for each VSS snapshot; timestamped filenames show VSS creation date; compare current hive vs historical snapshots to identify deleted/modified keys.
    526 
    527 ---
    528 
    529 ### Recovery Checklist
    530 
    531 - [ ] **Transaction logs present?** If YES: run with `--nl false` (default). If NO: run with `--nl true` (accept incomplete data), or use RLA.exe to attempt recovery.
    532 - [ ] **Recover deleted keys/values** — run with `--recover true` (default); review CSV output for deleted entries.
    533 - [ ] **Search slack space** — use `--ss` flag with search keywords; look for residual deleted data.
    534 - [ ] **Volume Shadow Copies available?** — use `--vss` to parse historical snapshots; compare current vs historical states.
    535 - [ ] **Output verification** — check CSV row count (compare with/without `--recover`); review `LastWriteTime` timestamps for anomalies; cross-reference with known-good baselines.
    536 
    537 ---
    538 
    539 ## Part 4: Troubleshooting
    540 
    541 | Problem | Cause | Solution |
    542 |---------|-------|----------|
    543 | `Unable to open file` | File locked, wrong path, permissions | Run as Administrator, verify path, close Registry Editor |
    544 | `Hive is dirty` | Missing transaction logs | Supply `.LOG1`/`.LOG2` files OR use RLA.exe OR run with `--nl true` |
    545 | Empty CSV output | Batch HiveType mismatch | Check batch file `HiveType` matches hive (e.g., NTUSER batch on NTUSER.DAT) |
    546 | ROT13 encoded values | Raw UserAssist output | Open CSV in Timeline Explorer (auto-decodes) |
    547 | `Out of memory` | Large hive + `--details` | Remove `--details`, use `--q`, increase system RAM |
    548 | Fewer rows without `--nl false` | Missing transaction log data | Ensure `.LOG1`/`.LOG2` present and `--nl false` used |
    549 
    550 ### Quick Fixes
    551 
    552 ```powershell
    553 # Check hive file is readable
    554 icacls C:\Cases\MyCase\Evidence\Hives\SYSTEM
    555 
    556 # Verify batch file exists
    557 dir C:\Cases\MyCase\Tools\RECmd\BatchExamples\DFIRBatch.reb
    558 
    559 # Test single key extraction (troubleshooting)
    560 RECmd.exe -f C:\Cases\MyCase\Evidence\Hives\SOFTWARE --kn "Microsoft\Windows NT\CurrentVersion" --csv C:\Cases\MyCase\Output\CSV --csvf Test.csv
    561 ```
    562 
    563 ---
    564 
    565 ## Part 5: Integration with Prefetch (PECmd)
    566 
    567 **Scenario:** Confirm program execution using multiple artefacts.
    568 
    569 ```powershell
    570 # Step 1: Extract prefetch with PECmd
    571 PECmd.exe -d C:\Cases\MyCase\Evidence\Prefetch --csv C:\Cases\MyCase\Output\CSV --csvf Prefetch.csv
    572 
    573 # Step 2: Extract BAM/DAM from SYSTEM hive
    574 RECmd.exe -f C:\Cases\MyCase\Evidence\Hives\SYSTEM --kn "ControlSet001\Services\bam\State\UserSettings" --csv C:\Cases\MyCase\Output\CSV --csvf BAM.csv
    575 
    576 # Step 3: Extract ShimCache from SYSTEM hive
    577 RECmd.exe -f C:\Cases\MyCase\Evidence\Hives\SYSTEM --kn "ControlSet001\Control\Session Manager\AppCompatCache" --csv C:\Cases\MyCase\Output\CSV --csvf ShimCache.csv
    578 
    579 # Step 4: Extract UserAssist from NTUSER.DAT
    580 RECmd.exe -f C:\Cases\MyCase\Evidence\Hives\NTUSER.DAT --kn "Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist" --csv C:\Cases\MyCase\Output\CSV --csvf UserAssist.csv
    581 ```
    582 
    583 **Step 5: Correlate in Timeline Explorer**
    584 
    585 | Artefact | Evidence Type | Timestamp Meaning | Correlation Key |
    586 |---------|---------------|-------------------|----------------|
    587 | **Prefetch** | Execution | Last 8 run times | `ExecutableName` |
    588 | **BAM/DAM** | Execution | Last execution time (per user SID) | Full path + SID |
    589 | **ShimCache** | File existence | File modified time (NOT execution) | Full path |
    590 | **UserAssist** | Execution (GUI apps) | Last execution time + run count | Executable name (ROT13 decoded) |
    591 
    592 Cross-referencing ShimCache (file created/modified), BAM (execution + SID), Prefetch (execution + run count), and UserAssist (execution + run count) around the same timestamp yields strong corroboration of execution by a specific user.
    593 
    594 ---
    595 
    596 ## Part 6: Custom Batch File Creation
    597 
    598 ### USB-Only Batch File
    599 
    600 Create `USB_Triage.reb`:
    601 
    602 ```yaml
    603 Description: USB device history extraction
    604 Author: YourName
    605 Version: 1.0
    606 Id: USB_Triage_001
    607 Keys:
    608   - Description: USB storage devices
    609     HiveType: SYSTEM
    610     Category: Devices
    611     KeyPath: ControlSet001\Enum\USBSTOR
    612     Recursive: true
    613     Comment: "VID, PID, serial number, FriendlyName"
    614 
    615   - Description: All USB devices
    616     HiveType: SYSTEM
    617     Category: Devices
    618     KeyPath: ControlSet001\Enum\USB
    619     Recursive: true
    620     Comment: "Includes non-storage USB devices"
    621 
    622   - Description: Mounted devices
    623     HiveType: SYSTEM
    624     Category: Devices
    625     KeyPath: MountedDevices
    626     Recursive: false
    627     Comment: "Drive letter to device mapping"
    628 ```
    629 
    630 ```powershell
    631 RECmd.exe -f C:\Cases\MyCase\Evidence\Hives\SYSTEM --bn USB_Triage.reb --csv C:\Cases\MyCase\Output\CSV --csvf USB.csv
    632 ```
    633 
    634 ---
    635 
    636 ### Persistence-Only Batch File
    637 
    638 Create `Persistence_Triage.reb`:
    639 
    640 ```yaml
    641 Description: Persistence triage (Run keys + Services)
    642 Author: YourName
    643 Version: 1.0
    644 Id: Persistence_Triage_001
    645 Keys:
    646   - Description: Run keys (machine)
    647     HiveType: SOFTWARE
    648     Category: Persistence
    649     KeyPath: Microsoft\Windows\CurrentVersion\Run
    650     Recursive: false
    651 
    652   - Description: RunOnce keys (machine)
    653     HiveType: SOFTWARE
    654     Category: Persistence
    655     KeyPath: Microsoft\Windows\CurrentVersion\RunOnce
    656     Recursive: false
    657 
    658   - Description: Run keys (user)
    659     HiveType: NTUSER
    660     Category: Persistence
    661     KeyPath: Software\Microsoft\Windows\CurrentVersion\Run
    662     Recursive: false
    663 
    664   - Description: Services
    665     HiveType: SYSTEM
    666     Category: Persistence
    667     KeyPath: ControlSet001\Services
    668     Recursive: true
    669     Comment: "Check ImagePath for unusual binaries"
    670 ```
    671 
    672 ```powershell
    673 RECmd.exe -d C:\Cases\MyCase\Evidence\Hives --bn Persistence_Triage.reb --csv C:\Cases\MyCase\Output\CSV --csvf Persistence_Quick.csv
    674 ```
    675 
    676 ---
    677 
    678 ## Part 7: Final Checklist
    679 
    680 **Pre-Analysis:**
    681 - [ ] RECmd.exe version verified (run `RECmd.exe` with no args)
    682 - [ ] Batch files updated (`RECmd.exe --sync`)
    683 - [ ] Hive files copied to evidence folder
    684 - [ ] Transaction logs (`.LOG1`, `.LOG2`) present alongside hives
    685 - [ ] Output directory created
    686 
    687 **Triage Execution:**
    688 - [ ] Run DFIRBatch against all hives
    689 - [ ] Open CSV in Timeline Explorer
    690 - [ ] Filter by Category: Program Execution, Persistence, User Activity, Devices
    691 - [ ] Export high-priority findings to report
    692 
    693 **Deep Dive:**
    694 - [ ] SAM: User accounts, logon times, RIDs
    695 - [ ] SECURITY: Audit policies (limited offline value)
    696 - [ ] SOFTWARE: OS info, Run keys, ProfileList, installed software
    697 - [ ] SYSTEM: USB devices, ShimCache, BAM/DAM, services, timezone
    698 - [ ] NTUSER.DAT: UserAssist, RecentDocs, ShellBags, searches, typed paths
    699 
    700 **Recovery & Correlation:**
    701 - [ ] Verify transaction logs replayed (`--nl false`)
    702 - [ ] Recover deleted keys/values (`--recover true`)
    703 - [ ] Search slack space for deleted data (`--ss`)
    704 - [ ] Parse VSS snapshots if available (`--vss`)
    705 - [ ] Correlate with PECmd prefetch output
    706 - [ ] Build execution timeline (Prefetch + BAM/DAM + UserAssist + ShimCache)
    707 
    708 **Quality Assurance:**
    709 - [ ] CSV row counts reasonable (not empty)
    710 - [ ] Timestamps in expected range (not year 1601 or 9999)
    711 - [ ] Timezone verified (SYSTEM\TimeZoneInformation)
    712 - [ ] Multiple NTUSER.DAT files processed (multi-user systems)
    713 - [ ] BAM/DAM SIDs mapped to usernames (via ProfileList)
    714 
    715 ---
    716 
    717 ## Quick Command Summary
    718 
    719 ```powershell
    720 # TRIAGE: All hives, DFIRBatch, UK timestamps
    721 RECmd.exe -d <HIVES_DIR> --bn BatchExamples\DFIRBatch.reb --csv <OUT_DIR> --csvf Triage.csv --q --dt "dd/MM/yyyy HH:mm:ss"
    722 
    723 # SINGLE HIVE: SOFTWARE example
    724 RECmd.exe -f <HIVES_DIR>\SOFTWARE --csv <OUT_DIR> --csvf SOFTWARE.csv --dt "dd/MM/yyyy HH:mm:ss"
    725 
    726 # PERSISTENCE: RegistryASEPs batch
    727 RECmd.exe -d <HIVES_DIR> --bn BatchExamples\RegistryASEPs.reb --csv <OUT_DIR> --csvf Persistence.csv
    728 
    729 # USB DEVICES: Extract from SYSTEM
    730 RECmd.exe -f <HIVES_DIR>\SYSTEM --kn "ControlSet001\Enum\USBSTOR" --csv <OUT_DIR> --csvf USB.csv
    731 
    732 # BAM EXECUTION: Extract from SYSTEM (Win10 1709+)
    733 RECmd.exe -f <HIVES_DIR>\SYSTEM --kn "ControlSet001\Services\bam\State\UserSettings" --csv <OUT_DIR> --csvf BAM.csv
    734 
    735 # USERASSIST: Extract from NTUSER.DAT
    736 RECmd.exe -f <HIVES_DIR>\NTUSER.DAT --kn "Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist" --csv <OUT_DIR> --csvf UserAssist.csv
    737 
    738 # SEARCH: Keyword across all hives
    739 RECmd.exe -d <HIVES_DIR> --sd "malware.exe" --csv <OUT_DIR> --csvf Search.csv
    740 
    741 # RECOVERY: Clean dirty hive with transaction logs
    742 RECmd.exe -f <HIVES_DIR>\SYSTEM --nl false --recover true --csv <OUT_DIR> --csvf SYSTEM_recovered.csv
    743 
    744 # RLA: Create clean hive from transaction logs
    745 RLA.exe -f <HIVES_DIR>\SYSTEM --out <HIVES_DIR>\Clean
    746 ```
    747 
    748 **Sources:**
    749 - RECmd GitHub: https://github.com/EricZimmerman/RECmd
    750 - Eric Zimmerman Tools: https://ericzimmerman.github.io/
    751 - SANS Windows Forensics Poster: https://www.sans.org/posters/windows-forensic-analysis/