Windows.Registry.UserAssist
Decodes UserAssist registry keys from NTUSER.DAT to reveal program execution counts and last run times.
Windows systems maintain a set of keys in the registry database (UserAssist keys) to keep track of programs that executed. The number of executions and last execution date and time are available in these keys.
The information within the binary UserAssist values contains only statistical data on the applications launched by the user via Windows Explorer. Programs launched via the commandline (cmd.exe) do not appear in these registry keys.
From a forensics perspective, being able to decode this information can be very useful.
Limitations: Additional data not parsed by Velociraptor is the FocusTime and FocusCount however these are not reliable. Also please note that some methods of viewing an executable will update the associated UserAssist key, and some methods of accessing an executable will not update the execution counter or time. Therefore there may be some executions that have a 0 time and 0 runcount.
name: Windows.Registry.UserAssist
description: |
Decodes UserAssist registry keys from NTUSER.DAT to reveal program
execution counts and last run times.
Windows systems maintain a set of keys in the registry database
(UserAssist keys) to keep track of programs that executed. The
number of executions and last execution date and time are available
in these keys.
The information within the binary UserAssist values contains only
statistical data on the applications launched by the user via
Windows Explorer. Programs launched via the commandline (cmd.exe)
do not appear in these registry keys.
From a forensics perspective, being able to decode this information
can be very useful.
**Limitations:** Additional data not parsed by Velociraptor is the
FocusTime and FocusCount however these are not reliable. Also please
note that some methods of viewing an executable will update the
associated UserAssist key, and some methods of accessing an
executable will not update the execution counter or time. Therefore
there may be some executions that have a 0 time and 0 runcount.
reference:
- https://www.aldeid.com/wiki/Windows-userassist-keys
precondition: SELECT OS From info() where OS = 'windows'
parameters:
- name: UserFilter
description: If specified we filter by this username.
type: regex
- name: ExecutionTimeAfter
type: timestamp
description: If specified only show executions after this time.
- name: UserAssistKey
default: Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\*\Count\*
export:
LET userAssistProfile = '''
[
["Header", 0, [
["NumberOfExecutions", 4, "uint32"],
["LastExecution", 60,"WinFileTime", {"type":"uint64"}]
]]
]
'''
LET _ExpandedTransforms <= dict(
`^c:`="C:",
`\\{008CA0B1-55B4-4C56-B8A8-4DE4B299D3BE\\}\\\\`="%APPDATA%\\Microsoft\\Windows\\AccountPictures\\",
`\\{724EF170-A42D-4FEF-9F26-B60E846FBA4F\\}\\\\`="%APPDATA%\\Microsoft\\Windows\\Start Menu\\Programs\\Administrative Tools\\",
`\\{B2C5E279-7ADD-439F-B28C-C41FE1BBF672\\}\\\\`="%LOCALAPPDATA%\\Desktop\\",
`\\{7BE16610-1F7F-44AC-BFF0-83E15F2FFCA1\\}\\\\`="%LOCALAPPDATA%\\Documents\\",
`\\{7CFBEFBC-DE1F-45AA-B843-A542AC536CC9\\}\\\\`="%LOCALAPPDATA%\\Favorites\\",
`\\{559D40A3-A036-40FA-AF61-84CB430A4D34\\}\\\\`="%LOCALAPPDATA%\\ProgramData\\",
`\\{A3918781-E5F2-4890-B3D9-A7E54332328C\\}\\\\`="%LOCALAPPDATA%\\Microsoft\\Windows\\Application Shortcuts\\",
`\\{AB5FB87B-7CE2-4F83-915D-550846C9537B\\}\\\\`="%USERPROFILE%\\Pictures\\Camera Roll\\",
`\\{9E52AB10-F80D-49DF-ACB8-4330F5687855\\}\\\\`="%LOCALAPPDATA%\\Microsoft\\Windows\\Burn\\Burn\\",
`\\{D0384E7D-BAC3-4797-8F14-CBA229B392B5\\}\\\\`="%ALLUSERSPROFILE%\\Microsoft\\Windows\\Start Menu\\Programs\\Administrative Tools\\",
`\\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D\\}\\\\`="%ALLUSERSPROFILE%\\OEM Links\\",
`\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8\\}\\\\`="%ALLUSERSPROFILE%\\Microsoft\\Windows\\Start Menu\\Programs\\",
`\\{A4115719-D62E-491D-AA7C-E74B8BE3B067\\}\\\\`="%ALLUSERSPROFILE%\\Microsoft\\Windows\\Start Menu\\",
`\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E\\}\\\\`="%ALLUSERSPROFILE%\\Microsoft\\Windows\\Start Menu\\Programs\\StartUp\\",
`\\{B94237E7-57AC-4347-9151-B08C6C32D1F7\\}\\\\`="%ALLUSERSPROFILE%\\Microsoft\\Windows\\Templates\\",
`\\{56784854-C6CB-462B-8169-88E350ACB882\\}\\\\`="%USERPROFILE%\\Contacts\\",
`\\{2B0F765D-C0E9-4171-908E-08A611B84FF6\\}\\\\`="%APPDATA%\\Microsoft\\Windows\\Cookies\\",
`\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641\\}\\\\`="%USERPROFILE%\\Desktop\\",
`\\{5CE4A5E9-E4EB-479D-B89F-130C02886155\\}\\\\`="%ALLUSERSPROFILE%\\Microsoft\\Windows\\DeviceMetadataStore\\",
`\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7\\}\\\\`="%USERPROFILE%\\Documents\\",
`\\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C\\}\\\\`="%APPDATA%\\Microsoft\\Windows\\Libraries\\Documents.library-ms\\",
`\\{374DE290-123F-4565-9164-39C4925E467B\\}\\\\`="%USERPROFILE%\\Downloads\\",
`\\{1777F761-68AD-4D8A-87BD-30B759FA33DD\\}\\\\`="%USERPROFILE%\\Favorites\\",
`\\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE\\}\\\\`="%windir%\\Fonts\\",
`\\{054FAE61-4DD8-4787-80B6-090220C4B700\\}\\\\`="%LOCALAPPDATA%\\Microsoft\\Windows\\GameExplorer\\",
`\\{D9DC8A3B-B784-432E-A781-5A1130A75963\\}\\\\`="%LOCALAPPDATA%\\Microsoft\\Windows\\History\\",
`\\{BCB5256F-79F6-4CEE-B725-DC34E402FD46\\}\\\\`="%APPDATA%\\Microsoft\\Internet Explorer\\Quick Launch\\User Pinned\\ImplicitAppShortcuts\\",
`\\{352481E8-33BE-4251-BA85-6007CAEDCF9D\\}\\\\`="%LOCALAPPDATA%\\Microsoft\\Windows\\Temporary Internet Files\\",
`\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE\\}\\\\`="%APPDATA%\\Microsoft\\Windows\\Libraries\\",
`\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968\\}\\\\`="%USERPROFILE%\\Links\\",
`\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091\\}\\\\`="%LOCALAPPDATA%\\",
`\\{A520A1A4-1780-4FF6-BD18-167343C5AF16\\}\\\\`="%USERPROFILE%\\AppData\\LocalLow\\",
`\\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC\\}\\\\`="%windir%\\resources\\0409\\",
`\\{4BD8D571-6D19-48D3-BE97-422220080E43\\}\\\\`="%USERPROFILE%\\Music\\",
`\\{2112AB0A-C86A-4FFE-A368-0DE96E47012E\\}\\\\`="%APPDATA%\\Microsoft\\Windows\\Libraries\\Music.library-ms\\",
`\\{C5ABBF53-E17F-4121-8900-86626FC2C973\\}\\\\`="%APPDATA%\\Microsoft\\Windows\\Network Shortcuts\\",
`\\{31C0DD25-9439-4F12-BF41-7FF4EDA38722\\}\\\\`="%USERPROFILE%\\3D Objects\\",
`\\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39\\}\\\\`="%LOCALAPPDATA%\\Microsoft\\Windows Photo Gallery\\Original Images\\",
`\\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C\\}\\\\`="%USERPROFILE%\\Pictures\\Slide Shows\\",
`\\{A990AE9F-A03B-4E80-94BC-9912D7504104\\}\\\\`="%APPDATA%\\Microsoft\\Windows\\Libraries\\Pictures.library-ms\\",
`\\{33E28130-4E1E-4676-835A-98395C3BC3BB\\}\\\\`="%USERPROFILE%\\Pictures\\",
`\\{DE92C1C7-837F-4F69-A3BB-86E631204A23\\}\\\\`="%USERPROFILE%\\Music\\Playlists\\",
`\\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4\\}\\\\`="%APPDATA%\\Microsoft\\Windows\\Printer Shortcuts\\",
`\\{5E6C858F-0E22-4760-9AFE-EA3317B67173\\}\\\\`="%USERPROFILE%\\",
`\\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97\\}\\\\`="%ALLUSERSPROFILE%\\",
`\\{905E63B6-C1BF-494E-B29C-65B732D3D21A\\}\\\\`="%ProgramFiles%\\",
`\\{6D809377-6AF0-444B-8957-A3773F02200E\\}\\\\`="%ProgramFiles%\\",
`\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E\\}\\\\`="%ProgramFiles%\\",
`\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066\\}\\\\`="%ProgramFiles%\\Common Files\\",
`\\{6365D5A7-0F0D-45E5-87F6-0DA56B6A4F7D\\}\\\\`="%ProgramFiles%\\Common Files\\",
`\\{DE974D24-D9C6-4D3E-BF91-F4455120B917\\}\\\\`="%ProgramFiles%\\Common Files\\",
`\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51\\}\\\\`="%APPDATA%\\Microsoft\\Windows\\Start Menu\\Programs\\",
`\\{DFDF76A2-C82A-4D63-906A-5644AC457385\\}\\\\`="%PUBLIC%\\",
`\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25\\}\\\\`="%PUBLIC%\\Desktop\\",
`\\{ED4824AF-DCE4-45A8-81E2-FC7965083634\\}\\\\`="%PUBLIC%\\Documents\\",
`\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0\\}\\\\`="%PUBLIC%\\Downloads\\",
`\\{DEBF2536-E1A8-4C59-B6A2-414586476AEA\\}\\\\`="%ALLUSERSPROFILE%\\Microsoft\\Windows\\GameExplorer\\",
`\\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384\\}\\\\`="%ALLUSERSPROFILE%\\Microsoft\\Windows\\Libraries\\",
`\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF\\}\\\\`="%PUBLIC%\\Music\\",
`\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5\\}\\\\`="%PUBLIC%\\Pictures\\",
`\\{E555AB60-153B-4D17-9F04-A5FE99FC15EC\\}\\\\`="%ALLUSERSPROFILE%\\Microsoft\\Windows\\Ringtones\\",
`\\{0482AF6C-08F1-4C34-8C90-E17EC98B1E17\\}\\\\`="%PUBLIC%\\AccountPictures\\",
`\\{2400183A-6185-49FB-A2D8-4A392A602BA3\\}\\\\`="%PUBLIC%\\Videos\\",
`\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F\\}\\\\`="%APPDATA%\\Microsoft\\Internet Explorer\\Quick Launch\\",
`\\{AE50C081-EBD2-438A-8655-8A092E34987A\\}\\\\`="%APPDATA%\\Microsoft\\Windows\\Recent\\",
`\\{1A6FDBA2-F42D-4358-A798-B74D745926C5\\}\\\\`="%PUBLIC%\\RecordedTV.library-ms\\",
`\\{8AD10C31-2ADB-4296-A8F7-E4701232C972\\}\\\\`="%windir%\\Resources\\",
`\\{C870044B-F49E-4126-A9C3-B52A1FF411E8\\}\\\\`="%LOCALAPPDATA%\\Microsoft\\Windows\\Ringtones\\",
`\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D\\}\\\\`="%APPDATA%\\",
`\\{AAA8D5A5-F1D6-4259-BAA8-78E7EF60835E\\}\\\\`="%LOCALAPPDATA%\\Microsoft\\Windows\\RoamedTileImages\\",
`\\{00BCFC5A-ED94-4E48-96A1-3F6217F21990\\}\\\\`="%LOCALAPPDATA%\\Microsoft\\Windows\\RoamingTiles\\",
`\\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F\\}\\\\`="%PUBLIC%\\Music\\Sample Music\\",
`\\{C4900540-2379-4C75-844B-64E6FAF8716B\\}\\\\`="%PUBLIC%\\Pictures\\Sample Pictures\\",
`\\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5\\}\\\\`="%PUBLIC%\\Music\\Sample Playlists\\",
`\\{859EAD94-2E85-48AD-A71A-0969CB56A6CD\\}\\\\`="%PUBLIC%\\Videos\\Sample Videos\\",
`\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4\\}\\\\`="%USERPROFILE%\\Saved Games\\",
`\\{3B193882-D3AD-4EAB-965A-69829D1FB59F\\}\\\\`="%USERPROFILE%\\Pictures\\Saved Pictures\\",
`\\{E25B5812-BE88-4BD9-94B0-29233477B6C3\\}\\\\`="%APPDATA%\\Microsoft\\Windows\\Libraries\\SavedPictures.library-ms\\",
`\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA\\}\\\\`="%USERPROFILE%\\Searches\\",
`\\{B7BEDE81-DF94-4682-A7D8-57A52620B86F\\}\\\\`="%USERPROFILE%\\Pictures\\Screenshots\\",
`\\{0D4C3DB6-03A3-462F-A0E6-08924C41B5D4\\}\\\\`="%LOCALAPPDATA%\\Microsoft\\Windows\\ConnectedSearch\\History\\",
`\\{7E636BFE-DFA9-4D5E-B456-D7B39851D8A9\\}\\\\`="%LOCALAPPDATA%\\Microsoft\\Windows\\ConnectedSearch\\Templates\\",
`\\{8983036C-27C0-404B-8F08-102D10DCFD74\\}\\\\`="%APPDATA%\\Microsoft\\Windows\\SendTo\\",
`\\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26\\}\\\\`="%ProgramFiles%\\Windows Sidebar\\Gadgets\\",
`\\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493\\}\\\\`="%LOCALAPPDATA%\\Microsoft\\Windows Sidebar\\Gadgets\\",
`\\{A52BBA46-E9E1-435F-B3D9-28DAA648C0F6\\}\\\\`="%USERPROFILE%\\OneDrive\\",
`\\{767E6811-49CB-4273-87C2-20F355E1085B\\}\\\\`="%USERPROFILE%\\OneDrive\\Pictures\\Camera Roll\\",
`\\{24D89E24-2F19-4534-9DDE-6A6671FBB8FE\\}\\\\`="%USERPROFILE%\\OneDrive\\Documents\\",
`\\{339719B5-8C47-4894-94C2-D8F77ADD44A6\\}\\\\`="%USERPROFILE%\\OneDrive\\Pictures\\",
`\\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19\\}\\\\`="%APPDATA%\\Microsoft\\Windows\\Start Menu\\",
`\\{B97D20BB-F46A-4C97-BA10-5E3608430854\\}\\\\`="%APPDATA%\\Microsoft\\Windows\\Start Menu\\Programs\\StartUp\\",
`\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7\\}\\\\`="%windir%\\system32\\",
`\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27\\}\\\\`="%windir%\\system32\\",
`\\{A63293E8-664E-48DB-A079-DF759E0509F7\\}\\\\`="%APPDATA%\\Microsoft\\Windows\\Templates\\",
`\\{9E3995AB-1F9C-4F13-B827-48B24B6C7174\\}\\\\`="%APPDATA%\\Microsoft\\Internet Explorer\\Quick Launch\\User Pinned\\",
`\\{0762D272-C50A-4BB0-A382-697DCD729B80\\}\\\\`="%SystemDrive%\\Users\\",
`\\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB\\}\\\\`="%LOCALAPPDATA%\\Programs\\",
`\\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516\\}\\\\`="%LOCALAPPDATA%\\Programs\\Common\\",
`\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC\\}\\\\`="%USERPROFILE%\\Videos\\",
`\\{491E922F-5643-4AF4-A7EB-4E7A138D8174\\}\\\\`="%APPDATA%\\Microsoft\\Windows\\Libraries\\Videos.library-ms\\",
`\\{F38BF404-1D43-42F2-9305-67DE0B28FC23\\}\\\\`="%windir%\\"
)
sources:
- query: |
LET TMP = SELECT OSPath.Path AS _KeyPath,
parse_string_with_regex(
string=OSPath.Path,
regex="^.+Count\\\\\"?(?P<Name>.+?)\"?$") AS Name,
OSPath,
parse_binary(
filename=Data.value,
accessor="data",
profile=userAssistProfile,
struct="Header"
) As ParsedUserAssist,
Username AS User
FROM Artifact.Windows.Registry.NTUser(KeyGlob=UserAssistKey)
LET UserAssist = SELECT _KeyPath,
if(condition=Name.Name,
then=rot13(string=Name.Name),
else=OSPath.Path) AS Name,
User,
ParsedUserAssist.LastExecution As LastExecution,
ParsedUserAssist.NumberOfExecutions AS NumberOfExecutions
FROM TMP
ORDER BY LastExecution
LET A1 = SELECT * FROM if(
condition=UserFilter,
then={ SELECT * FROM UserAssist WHERE User =~ UserFilter },
else={ SELECT * FROM UserAssist })
LET get_path(path) = regex_transform(source=lowcase(string=path),map=_ExpandedTransforms)
LET results = SELECT
get_path(path=Name) as Name,
expand(path=get_path(path=Name)) as Expanded,
User,
if(condition= LastExecution < "1700-01-01",
then= "",
else= LastExecution ) as LastExecution,
NumberOfExecutions
FROM if(
condition=ExecutionTimeAfter,
then={
SELECT * FROM A1 WHERE LastExecutionTS > ExecutionTimeAfter
},
else={ SELECT * FROM A1})
WHERE NOT Name =~ '^UEME_'
SELECT
if(condition = split(string=Name,sep='''%[^%]+%''')[1] = Expanded,
then = Name,
else = Expanded ) as Name,
User,
LastExecution,
NumberOfExecutions
FROM results