Skip to content
Please update to the latest release 0.77.2 to address Multiple CVEs.
Windows.Registry.UserAssist

Windows.Registry.UserAssist

Decodes UserAssist registry keys from NTUSER.DAT to reveal program execution counts and last run times.

Windows systems maintain a set of keys in the registry database (UserAssist keys) to keep track of programs that executed. The number of executions and last execution date and time are available in these keys.

The information within the binary UserAssist values contains only statistical data on the applications launched by the user via Windows Explorer. Programs launched via the command­line (cmd.exe) do not appear in these registry keys.

From a forensics perspective, being able to decode this information can be very useful.

Limitations: Additional data not parsed by Velociraptor is the FocusTime and FocusCount however these are not reliable. Also please note that some methods of viewing an executable will update the associated UserAssist key, and some methods of accessing an executable will not update the execution counter or time. Therefore there may be some executions that have a 0 time and 0 runcount.


name: Windows.Registry.UserAssist
description: |
  Decodes UserAssist registry keys from NTUSER.DAT to reveal program
  execution counts and last run times.

  Windows systems maintain a set of keys in the registry database
  (UserAssist keys) to keep track of programs that executed. The
  number of executions and last execution date and time are available
  in these keys.

  The information within the binary UserAssist values contains only
  statistical data on the applications launched by the user via
  Windows Explorer. Programs launched via the command­line (cmd.exe)
  do not appear in these registry keys.

  From a forensics perspective, being able to decode this information
  can be very useful.

  **Limitations:** Additional data not parsed by Velociraptor is the
  FocusTime and FocusCount however these are not reliable. Also please
  note that some methods of viewing an executable will update the
  associated UserAssist key, and some methods of accessing an
  executable will not update the execution counter or time. Therefore
  there may be some executions that have a 0 time and 0 runcount.

reference:
  - https://www.aldeid.com/wiki/Windows-userassist-keys

precondition: SELECT OS From info() where OS = 'windows'

parameters:
  - name: UserFilter
    description: If specified we filter by this username.
    type: regex

  - name: ExecutionTimeAfter
    type: timestamp
    description: If specified only show executions after this time.

  - name: UserAssistKey
    default: Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\*\Count\*

export:
  LET userAssistProfile = '''
      [
        ["Header", 0, [
          ["NumberOfExecutions", 4, "uint32"],
          ["LastExecution", 60,"WinFileTime", {"type":"uint64"}]
        ]]
      ]
    '''
  LET _ExpandedTransforms <= dict(
        `^c:`="C:",
        `\\{008CA0B1-55B4-4C56-B8A8-4DE4B299D3BE\\}\\\\`="%APPDATA%\\Microsoft\\Windows\\AccountPictures\\",
        `\\{724EF170-A42D-4FEF-9F26-B60E846FBA4F\\}\\\\`="%APPDATA%\\Microsoft\\Windows\\Start Menu\\Programs\\Administrative Tools\\",
        `\\{B2C5E279-7ADD-439F-B28C-C41FE1BBF672\\}\\\\`="%LOCALAPPDATA%\\Desktop\\",
        `\\{7BE16610-1F7F-44AC-BFF0-83E15F2FFCA1\\}\\\\`="%LOCALAPPDATA%\\Documents\\",
        `\\{7CFBEFBC-DE1F-45AA-B843-A542AC536CC9\\}\\\\`="%LOCALAPPDATA%\\Favorites\\",
        `\\{559D40A3-A036-40FA-AF61-84CB430A4D34\\}\\\\`="%LOCALAPPDATA%\\ProgramData\\",
        `\\{A3918781-E5F2-4890-B3D9-A7E54332328C\\}\\\\`="%LOCALAPPDATA%\\Microsoft\\Windows\\Application Shortcuts\\",
        `\\{AB5FB87B-7CE2-4F83-915D-550846C9537B\\}\\\\`="%USERPROFILE%\\Pictures\\Camera Roll\\",
        `\\{9E52AB10-F80D-49DF-ACB8-4330F5687855\\}\\\\`="%LOCALAPPDATA%\\Microsoft\\Windows\\Burn\\Burn\\",
        `\\{D0384E7D-BAC3-4797-8F14-CBA229B392B5\\}\\\\`="%ALLUSERSPROFILE%\\Microsoft\\Windows\\Start Menu\\Programs\\Administrative Tools\\",
        `\\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D\\}\\\\`="%ALLUSERSPROFILE%\\OEM Links\\",
        `\\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8\\}\\\\`="%ALLUSERSPROFILE%\\Microsoft\\Windows\\Start Menu\\Programs\\",
        `\\{A4115719-D62E-491D-AA7C-E74B8BE3B067\\}\\\\`="%ALLUSERSPROFILE%\\Microsoft\\Windows\\Start Menu\\",
        `\\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E\\}\\\\`="%ALLUSERSPROFILE%\\Microsoft\\Windows\\Start Menu\\Programs\\StartUp\\",
        `\\{B94237E7-57AC-4347-9151-B08C6C32D1F7\\}\\\\`="%ALLUSERSPROFILE%\\Microsoft\\Windows\\Templates\\",
        `\\{56784854-C6CB-462B-8169-88E350ACB882\\}\\\\`="%USERPROFILE%\\Contacts\\",
        `\\{2B0F765D-C0E9-4171-908E-08A611B84FF6\\}\\\\`="%APPDATA%\\Microsoft\\Windows\\Cookies\\",
        `\\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641\\}\\\\`="%USERPROFILE%\\Desktop\\",
        `\\{5CE4A5E9-E4EB-479D-B89F-130C02886155\\}\\\\`="%ALLUSERSPROFILE%\\Microsoft\\Windows\\DeviceMetadataStore\\",
        `\\{FDD39AD0-238F-46AF-ADB4-6C85480369C7\\}\\\\`="%USERPROFILE%\\Documents\\",
        `\\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C\\}\\\\`="%APPDATA%\\Microsoft\\Windows\\Libraries\\Documents.library-ms\\",
        `\\{374DE290-123F-4565-9164-39C4925E467B\\}\\\\`="%USERPROFILE%\\Downloads\\",
        `\\{1777F761-68AD-4D8A-87BD-30B759FA33DD\\}\\\\`="%USERPROFILE%\\Favorites\\",
        `\\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE\\}\\\\`="%windir%\\Fonts\\",
        `\\{054FAE61-4DD8-4787-80B6-090220C4B700\\}\\\\`="%LOCALAPPDATA%\\Microsoft\\Windows\\GameExplorer\\",
        `\\{D9DC8A3B-B784-432E-A781-5A1130A75963\\}\\\\`="%LOCALAPPDATA%\\Microsoft\\Windows\\History\\",
        `\\{BCB5256F-79F6-4CEE-B725-DC34E402FD46\\}\\\\`="%APPDATA%\\Microsoft\\Internet Explorer\\Quick Launch\\User Pinned\\ImplicitAppShortcuts\\",
        `\\{352481E8-33BE-4251-BA85-6007CAEDCF9D\\}\\\\`="%LOCALAPPDATA%\\Microsoft\\Windows\\Temporary Internet Files\\",
        `\\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE\\}\\\\`="%APPDATA%\\Microsoft\\Windows\\Libraries\\",
        `\\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968\\}\\\\`="%USERPROFILE%\\Links\\",
        `\\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091\\}\\\\`="%LOCALAPPDATA%\\",
        `\\{A520A1A4-1780-4FF6-BD18-167343C5AF16\\}\\\\`="%USERPROFILE%\\AppData\\LocalLow\\",
        `\\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC\\}\\\\`="%windir%\\resources\\0409\\",
        `\\{4BD8D571-6D19-48D3-BE97-422220080E43\\}\\\\`="%USERPROFILE%\\Music\\",
        `\\{2112AB0A-C86A-4FFE-A368-0DE96E47012E\\}\\\\`="%APPDATA%\\Microsoft\\Windows\\Libraries\\Music.library-ms\\",
        `\\{C5ABBF53-E17F-4121-8900-86626FC2C973\\}\\\\`="%APPDATA%\\Microsoft\\Windows\\Network Shortcuts\\",
        `\\{31C0DD25-9439-4F12-BF41-7FF4EDA38722\\}\\\\`="%USERPROFILE%\\3D Objects\\",
        `\\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39\\}\\\\`="%LOCALAPPDATA%\\Microsoft\\Windows Photo Gallery\\Original Images\\",
        `\\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C\\}\\\\`="%USERPROFILE%\\Pictures\\Slide Shows\\",
        `\\{A990AE9F-A03B-4E80-94BC-9912D7504104\\}\\\\`="%APPDATA%\\Microsoft\\Windows\\Libraries\\Pictures.library-ms\\",
        `\\{33E28130-4E1E-4676-835A-98395C3BC3BB\\}\\\\`="%USERPROFILE%\\Pictures\\",
        `\\{DE92C1C7-837F-4F69-A3BB-86E631204A23\\}\\\\`="%USERPROFILE%\\Music\\Playlists\\",
        `\\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4\\}\\\\`="%APPDATA%\\Microsoft\\Windows\\Printer Shortcuts\\",
        `\\{5E6C858F-0E22-4760-9AFE-EA3317B67173\\}\\\\`="%USERPROFILE%\\",
        `\\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97\\}\\\\`="%ALLUSERSPROFILE%\\",
        `\\{905E63B6-C1BF-494E-B29C-65B732D3D21A\\}\\\\`="%ProgramFiles%\\",
        `\\{6D809377-6AF0-444B-8957-A3773F02200E\\}\\\\`="%ProgramFiles%\\",
        `\\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E\\}\\\\`="%ProgramFiles%\\",
        `\\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066\\}\\\\`="%ProgramFiles%\\Common Files\\",
        `\\{6365D5A7-0F0D-45E5-87F6-0DA56B6A4F7D\\}\\\\`="%ProgramFiles%\\Common Files\\",
        `\\{DE974D24-D9C6-4D3E-BF91-F4455120B917\\}\\\\`="%ProgramFiles%\\Common Files\\",
        `\\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51\\}\\\\`="%APPDATA%\\Microsoft\\Windows\\Start Menu\\Programs\\",
        `\\{DFDF76A2-C82A-4D63-906A-5644AC457385\\}\\\\`="%PUBLIC%\\",
        `\\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25\\}\\\\`="%PUBLIC%\\Desktop\\",
        `\\{ED4824AF-DCE4-45A8-81E2-FC7965083634\\}\\\\`="%PUBLIC%\\Documents\\",
        `\\{3D644C9B-1FB8-4F30-9B45-F670235F79C0\\}\\\\`="%PUBLIC%\\Downloads\\",
        `\\{DEBF2536-E1A8-4C59-B6A2-414586476AEA\\}\\\\`="%ALLUSERSPROFILE%\\Microsoft\\Windows\\GameExplorer\\",
        `\\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384\\}\\\\`="%ALLUSERSPROFILE%\\Microsoft\\Windows\\Libraries\\",
        `\\{3214FAB5-9757-4298-BB61-92A9DEAA44FF\\}\\\\`="%PUBLIC%\\Music\\",
        `\\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5\\}\\\\`="%PUBLIC%\\Pictures\\",
        `\\{E555AB60-153B-4D17-9F04-A5FE99FC15EC\\}\\\\`="%ALLUSERSPROFILE%\\Microsoft\\Windows\\Ringtones\\",
        `\\{0482AF6C-08F1-4C34-8C90-E17EC98B1E17\\}\\\\`="%PUBLIC%\\AccountPictures\\",
        `\\{2400183A-6185-49FB-A2D8-4A392A602BA3\\}\\\\`="%PUBLIC%\\Videos\\",
        `\\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F\\}\\\\`="%APPDATA%\\Microsoft\\Internet Explorer\\Quick Launch\\",
        `\\{AE50C081-EBD2-438A-8655-8A092E34987A\\}\\\\`="%APPDATA%\\Microsoft\\Windows\\Recent\\",
        `\\{1A6FDBA2-F42D-4358-A798-B74D745926C5\\}\\\\`="%PUBLIC%\\RecordedTV.library-ms\\",
        `\\{8AD10C31-2ADB-4296-A8F7-E4701232C972\\}\\\\`="%windir%\\Resources\\",
        `\\{C870044B-F49E-4126-A9C3-B52A1FF411E8\\}\\\\`="%LOCALAPPDATA%\\Microsoft\\Windows\\Ringtones\\",
        `\\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D\\}\\\\`="%APPDATA%\\",
        `\\{AAA8D5A5-F1D6-4259-BAA8-78E7EF60835E\\}\\\\`="%LOCALAPPDATA%\\Microsoft\\Windows\\RoamedTileImages\\",
        `\\{00BCFC5A-ED94-4E48-96A1-3F6217F21990\\}\\\\`="%LOCALAPPDATA%\\Microsoft\\Windows\\RoamingTiles\\",
        `\\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F\\}\\\\`="%PUBLIC%\\Music\\Sample Music\\",
        `\\{C4900540-2379-4C75-844B-64E6FAF8716B\\}\\\\`="%PUBLIC%\\Pictures\\Sample Pictures\\",
        `\\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5\\}\\\\`="%PUBLIC%\\Music\\Sample Playlists\\",
        `\\{859EAD94-2E85-48AD-A71A-0969CB56A6CD\\}\\\\`="%PUBLIC%\\Videos\\Sample Videos\\",
        `\\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4\\}\\\\`="%USERPROFILE%\\Saved Games\\",
        `\\{3B193882-D3AD-4EAB-965A-69829D1FB59F\\}\\\\`="%USERPROFILE%\\Pictures\\Saved Pictures\\",
        `\\{E25B5812-BE88-4BD9-94B0-29233477B6C3\\}\\\\`="%APPDATA%\\Microsoft\\Windows\\Libraries\\SavedPictures.library-ms\\",
        `\\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA\\}\\\\`="%USERPROFILE%\\Searches\\",
        `\\{B7BEDE81-DF94-4682-A7D8-57A52620B86F\\}\\\\`="%USERPROFILE%\\Pictures\\Screenshots\\",
        `\\{0D4C3DB6-03A3-462F-A0E6-08924C41B5D4\\}\\\\`="%LOCALAPPDATA%\\Microsoft\\Windows\\ConnectedSearch\\History\\",
        `\\{7E636BFE-DFA9-4D5E-B456-D7B39851D8A9\\}\\\\`="%LOCALAPPDATA%\\Microsoft\\Windows\\ConnectedSearch\\Templates\\",
        `\\{8983036C-27C0-404B-8F08-102D10DCFD74\\}\\\\`="%APPDATA%\\Microsoft\\Windows\\SendTo\\",
        `\\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26\\}\\\\`="%ProgramFiles%\\Windows Sidebar\\Gadgets\\",
        `\\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493\\}\\\\`="%LOCALAPPDATA%\\Microsoft\\Windows Sidebar\\Gadgets\\",
        `\\{A52BBA46-E9E1-435F-B3D9-28DAA648C0F6\\}\\\\`="%USERPROFILE%\\OneDrive\\",
        `\\{767E6811-49CB-4273-87C2-20F355E1085B\\}\\\\`="%USERPROFILE%\\OneDrive\\Pictures\\Camera Roll\\",
        `\\{24D89E24-2F19-4534-9DDE-6A6671FBB8FE\\}\\\\`="%USERPROFILE%\\OneDrive\\Documents\\",
        `\\{339719B5-8C47-4894-94C2-D8F77ADD44A6\\}\\\\`="%USERPROFILE%\\OneDrive\\Pictures\\",
        `\\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19\\}\\\\`="%APPDATA%\\Microsoft\\Windows\\Start Menu\\",
        `\\{B97D20BB-F46A-4C97-BA10-5E3608430854\\}\\\\`="%APPDATA%\\Microsoft\\Windows\\Start Menu\\Programs\\StartUp\\",
        `\\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7\\}\\\\`="%windir%\\system32\\",
        `\\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27\\}\\\\`="%windir%\\system32\\",
        `\\{A63293E8-664E-48DB-A079-DF759E0509F7\\}\\\\`="%APPDATA%\\Microsoft\\Windows\\Templates\\",
        `\\{9E3995AB-1F9C-4F13-B827-48B24B6C7174\\}\\\\`="%APPDATA%\\Microsoft\\Internet Explorer\\Quick Launch\\User Pinned\\",
        `\\{0762D272-C50A-4BB0-A382-697DCD729B80\\}\\\\`="%SystemDrive%\\Users\\",
        `\\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB\\}\\\\`="%LOCALAPPDATA%\\Programs\\",
        `\\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516\\}\\\\`="%LOCALAPPDATA%\\Programs\\Common\\",
        `\\{18989B1D-99B5-455B-841C-AB7C74E4DDFC\\}\\\\`="%USERPROFILE%\\Videos\\",
        `\\{491E922F-5643-4AF4-A7EB-4E7A138D8174\\}\\\\`="%APPDATA%\\Microsoft\\Windows\\Libraries\\Videos.library-ms\\",
        `\\{F38BF404-1D43-42F2-9305-67DE0B28FC23\\}\\\\`="%windir%\\"
    )

sources:
  - query: |
      LET TMP = SELECT OSPath.Path AS _KeyPath,
          parse_string_with_regex(
                string=OSPath.Path,
                regex="^.+Count\\\\\"?(?P<Name>.+?)\"?$") AS Name,
            OSPath,
            parse_binary(
               filename=Data.value,
               accessor="data",
               profile=userAssistProfile,
               struct="Header"
             ) As ParsedUserAssist,
             Username AS User
      FROM Artifact.Windows.Registry.NTUser(KeyGlob=UserAssistKey)

      LET UserAssist = SELECT _KeyPath,
          if(condition=Name.Name,
             then=rot13(string=Name.Name),
             else=OSPath.Path) AS Name,
          User,
          ParsedUserAssist.LastExecution As LastExecution,
          ParsedUserAssist.NumberOfExecutions AS NumberOfExecutions
        FROM TMP
        ORDER BY LastExecution

      LET A1 = SELECT * FROM if(
          condition=UserFilter,
          then={ SELECT * FROM UserAssist WHERE User =~ UserFilter },
          else={ SELECT * FROM UserAssist })


      LET get_path(path) = regex_transform(source=lowcase(string=path),map=_ExpandedTransforms)

      LET results = SELECT
          get_path(path=Name) as Name,
          expand(path=get_path(path=Name)) as Expanded,
          User,
          if(condition= LastExecution < "1700-01-01",
                  then= "",
                  else= LastExecution ) as LastExecution,
          NumberOfExecutions
        FROM if(
            condition=ExecutionTimeAfter,
            then={
              SELECT * FROM A1 WHERE LastExecutionTS > ExecutionTimeAfter
            },
            else={ SELECT * FROM A1})
        WHERE NOT Name =~ '^UEME_'

      SELECT
        if(condition = split(string=Name,sep='''%[^%]+%''')[1] = Expanded,
                then = Name,
                else = Expanded ) as Name,
        User,
        LastExecution,
        NumberOfExecutions
      FROM results