reg-user-assists

Loads information such as "a list of programs recently executed, the last run time, and the execution count" stored in the registry. You can check the name and list of recently executed applications with the loaded data and use the time and number of recently executed applications for analysis.

Syntax

reg-user-assists [zippath=ZIPFILE_PATH] FILE_PATH
Required Parameters
FILE_PATH
Path to the registry file. If you provided the zippath option, input the file path in the ZIP file.
Optional Parameters
zippath=ZIPFILE_PATH
Path to the ZIP file.

Description

After running the reg-user-assists command, the output fields are as follows:

FieldTypeDescription
keyStringExecutable file path
session_numIntegerSession number
exec_countIntegerNumber of times of execution
focus_timeIntegerTime activated
last_executionDateLast run time
last_writtenDateLast written time

Usage

  1. Retrieve by providing the file path.

    reg-user-assists /opt/logpresso/testdata/registry/test/NTUSER.DAT
    
  2. Retrieve when the zippath option is provided.

    reg-user-assists zippath=/opt/logpresso/testdata/registry.zip registry/test/NTUSER.DAT