Skip to content

Added WOW6432Node Run Keys and Expanded Edge and Chrome Artifacts#111

Merged
AndrewRathbun merged 1 commit intoEricZimmerman:masterfrom
reece394:recmd-dfirbatch
Jan 6, 2026
Merged

Added WOW6432Node Run Keys and Expanded Edge and Chrome Artifacts#111
AndrewRathbun merged 1 commit intoEricZimmerman:masterfrom
reece394:recmd-dfirbatch

Conversation

@reece394
Copy link
Copy Markdown
Contributor

@reece394 reece394 commented Jan 6, 2026

Description

This adds support for the WOW6432Node Run and RunOnce keys used for 32 bit software on 64 bit systems. This is only present on HKLM and does not work on NTUSER hence only doing HKLM. Additionally I allowed Chrome and Edge keys to be a bit less restrictive to include the different editions of Chrome and Edge such as Dev, Canary and Beta.

Checklist:

Please replace every instance of [ ] with [X] OR click on the checkboxes after you submit your PR

  • I have generated a unique GUID for my Batch file(s)
  • I have tested and validated the new Batch file(s) against test data and achieved the desired output
  • I have placed the Batch file(s) within the .\RECmd\BatchExamples directory
  • I have set or updated the version of my Batch file(s)
  • I have made an attempt to document the artifacts within the Batch file(s)
  • I have consulted the Guide/Template to ensure my Map(s) follow the same format

Thank you for your submission and for contributing to the DFIR community!

Copy link
Copy Markdown
Collaborator

@AndrewRathbun AndrewRathbun left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you as always 💯

@AndrewRathbun AndrewRathbun merged commit 706dce7 into EricZimmerman:master Jan 6, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants