Important Notice: On February 29th, this community was put into read-only mode. All existing posts will remain but customers are unable to add new posts or comment on existing. Please feel to join our Community Discord for any questions and discussions.

Reg Key scan issues

Hello All,

hopefully someone cal help me here as i am quiet confused. I am trying to Scan Profile to find the following reg key -

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\Credential Providers{11660363-49E2-4F87-AB2E-FD210019AE88}

when i add this into the scan profile as shown exactly above it doesnt not find it. Here is the profile config in image 1

when i add a \ to the end of the profile, it does pull back a result but its the wrong key all together. what am i doing wrong please?

i do hope this makes sense as im quiet new to the service

Profile Example

Reg example

0

Comments

3 comments
Date Votes
  • Hi,

    i'm not sure what you mean or what you want because everything looks fine on you screenshots.

    End the line with \ or **\ to see all values under a key (like on your screenshot - "default" and "WrappedCLSID")

    All values:

    SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\Credential Providers\{11660363-49E2-4F87-AB2E-FD210019AE88}\**\

    Or end the line with the specific value you are looking for (in this case "WrappedCLSID"):

    Specific entry:

    SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\Credential Providers\{11660363-49E2-4F87-AB2E-FD210019AE88}\WrappedCLSID

    If you try to find every key with the value "WrappedCLSID" inside you should try this:

    SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\Credential Providers\**\WrappedCLSID

    0
  • Hi Christian

    Thank you for the reply.

    What i am looking for is - {11660363-381B-42A5-893E-BBF09122F76A}

    i need to modify this to _{11660363-381B-42A5-893E-BBF09122F76A}

    so i am looking for all PC's with this key

    0
  • Ok in understand, then use the value to find all keys

    First reg scan for the "WrappedCLSID" under the key {11660363-49E2-4F87-AB2E-FD210019AE88}:

    SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\Credential Providers{11660363-49E2-4F87-AB2E-FD210019AE88}\WrappedCLSID

    If the key exists, you can see him under -> device -> registry in Inventory with the path to the key

    enter image description here

    Now Create a Collection and use path -> equals

    enter image description here

    And if you scan for the "new" key too, you can find all changed devices too:

    SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\Credential Providers_{11660363-49E2-4F87-AB2E-FD210019AE88}\WrappedCLSID

    enter image description here

    0