viewer9 documentation

RegOpenKey PML Operation

RegAccess ("Desired Access" in Procmon) is bit flags.

RegAccessGranted ("Granted Access" in Procmon) is returned in evresults. This field is not always displayed in Procmon, but is displayed when it is different from the Desired Access. For example if the RegAccess requested is "Max Allowed", the RegAccessGranted might be "All Access" or just "Read". Here is a query to display the ResultCode and those two fields: q Op=RegOpenKey ResultCode RegAccess RegAccessGranted

Example from 32-bit PML

Hover over field values like Time, ResultCode, RegAccess, RegAccessGranted, RegDispos, and bytes of evdata and evresults in this example to see tooltips as they appear in viewer9. The tooltip of the first byte of a color patch tells the field name.

RegOpenKey opcode=2,0

ev=58

Time:2022-05-17 14:24:30.9881471
Duration:0.0000046
ResultCode:SUCCESS
Tid:3976
Path:HKLM\System\CurrentControlSet\Control\DeviceClasses\{0850302a-b344-4fda-9be9-90576b8d46f0}
RegAccess:Query Value
RegAccessGranted:Query Value

evdata[0-99] file offset 7953

05a 80 69 00 01 00 00 00 Z.i.....
848 4b 4c 4d 5c 53 79 73 HKLM\Sys
1674 65 6d 5c 43 75 72 72 tem\Curr
2465 6e 74 43 6f 6e 74 72 entContr
326f 6c 53 65 74 5c 43 6f olSet\Co
406e 74 72 6f 6c 5c 44 65 ntrol\De
4876 69 63 65 43 6c 61 73 viceClas
5673 65 73 5c 7b 30 38 35 ses\.085
6430 33 30 32 61 2d 62 33 0302a-b3
7234 34 2d 34 66 64 61 2d 44-4fda-
8039 62 65 39 2d 39 30 35 9be9-905
8837 36 62 38 64 34 36 66 76b8d46f
9630 7d 6b 81 0.k.

evresults[0-7] file offset 8055

001 00 00 00 00 00 00 00 ........

Call Stack stacksize=45

StackAddressmodModNameModPath
0x816d40c871ntoskrnl.exe + 0x26b0c8C:\Windows\system32\ntoskrnl.exe
0x8184cbfc71ntoskrnl.exe + 0x3e3bfcC:\Windows\system32\ntoskrnl.exe
0x817686dd71ntoskrnl.exe + 0x2ff6ddC:\Windows\system32\ntoskrnl.exe
0x816d1c3a71ntoskrnl.exe + 0x268c3aC:\Windows\system32\ntoskrnl.exe
0x816d0ed571ntoskrnl.exe + 0x267ed5C:\Windows\system32\ntoskrnl.exe
0x816ccfba71ntoskrnl.exe + 0x263fbaC:\Windows\system32\ntoskrnl.exe
0x8155ce2b71ntoskrnl.exe + 0xf3e2bC:\Windows\system32\ntoskrnl.exe
0x8154ad7171ntoskrnl.exe + 0xe1d71C:\Windows\system32\ntoskrnl.exe
0x816b3fbf71ntoskrnl.exe + 0x24afbfC:\Windows\system32\ntoskrnl.exe
0x816ace4471ntoskrnl.exe + 0x243e44C:\Windows\system32\ntoskrnl.exe
0x816acd2f71ntoskrnl.exe + 0x243d2fC:\Windows\system32\ntoskrnl.exe
0x816a922d71ntoskrnl.exe + 0x24022dC:\Windows\system32\ntoskrnl.exe
0x816a90f871ntoskrnl.exe + 0x2400f8C:\Windows\system32\ntoskrnl.exe
0x816a902671ntoskrnl.exe + 0x240026C:\Windows\system32\ntoskrnl.exe
0x816c1a7371ntoskrnl.exe + 0x258a73C:\Windows\system32\ntoskrnl.exe
0x816c196c71ntoskrnl.exe + 0x25896cC:\Windows\system32\ntoskrnl.exe
0x816c142671ntoskrnl.exe + 0x258426C:\Windows\system32\ntoskrnl.exe
0x816c062f71ntoskrnl.exe + 0x25762fC:\Windows\system32\ntoskrnl.exe
0x816c009671ntoskrnl.exe + 0x257096C:\Windows\system32\ntoskrnl.exe
0x816c004c71ntoskrnl.exe + 0x25704cC:\Windows\system32\ntoskrnl.exe
0x816c001c71ntoskrnl.exe + 0x25701cC:\Windows\system32\ntoskrnl.exe
0x81760dbf71ntoskrnl.exe + 0x2f7dbfC:\Windows\system32\ntoskrnl.exe
0x8173313e71ntoskrnl.exe + 0x2ca13eC:\Windows\system32\ntoskrnl.exe
0x8155ce2b71ntoskrnl.exe + 0xf3e2bC:\Windows\system32\ntoskrnl.exe
0x7714b65a57ntdll.dll + 0x6b65aC:\Windows\SYSTEM32\ntdll.dll
0x74b811a137KERNELBASE.dll + 0x111a1C:\Windows\system32\KERNELBASE.dll
0x754240ca46KERNEL32.DLL + 0x40caC:\Windows\system32\KERNEL32.DLL
0x74c55a1467cfgmgr32.dll + 0x5a14C:\Windows\system32\CFGMGR32.dll
0x74c55b0467cfgmgr32.dll + 0x5b04C:\Windows\system32\CFGMGR32.dll
0x74c5673e67cfgmgr32.dll + 0x673eC:\Windows\system32\CFGMGR32.dll
0x74c5667e67cfgmgr32.dll + 0x667eC:\Windows\system32\CFGMGR32.dll
0x73a5438c278DEVOBJ.dll + 0x438cc:\windows\system32\DEVOBJ.dll
0x6a0126a4585BluetoothApis.dll + 0x26a4C:\Windows\System32\BluetoothApis.dll
0x6a2eaa88586bthprops.cpl + 0xaa88C:\Windows\System32\bthprops.cpl
0x5b2243e5707chrome.dll + 0x70b43e5C:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll
0x5a8c77d3707chrome.dll + 0x67577d3C:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll
0x56f4b830707chrome.dll + 0x2ddb830C:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll
0x57623585707chrome.dll + 0x34b3585C:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll
0x57622e5c707chrome.dll + 0x34b2e5cC:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll
0x57621af8707chrome.dll + 0x34b1af8C:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll
0x544aa3d5707chrome.dll + 0x33a3d5C:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll
0x54992e91707chrome.dll + 0x822e91C:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll
0x754241a846KERNEL32.DLL + 0x41a8C:\Windows\system32\KERNEL32.DLL
0x77132e3157ntdll.dll + 0x52e31C:\Windows\SYSTEM32\ntdll.dll
0x77132dff57ntdll.dll + 0x52dffC:\Windows\SYSTEM32\ntdll.dll

See also

Posted 4 Jul 2022 last updated 15 Nov 2022   As viewer9 is just starting out, discussion is invited via email. Please send questions and comments to forum@viewer9.com directly. Threads that might be valuable to other users will be posted as part of the documentation. Posted messages will not include your address or your full name, and might be shortened for brevity.

Copyright 2022, bryantlite, Inc.