viewer9 documentation | Index Home |
RegOpenKey PML Operation
RegAccess ("Desired Access" in Procmon) is bit flags.
RegAccessGranted ("Granted Access" in Procmon) is returned in evresults. This field is not always displayed in Procmon, but is displayed when it is different from the Desired Access. For example if the RegAccess requested is "Max Allowed", the RegAccessGranted might be "All Access" or just "Read". Here is a query to display the ResultCode and those two fields: q Op=RegOpenKey ResultCode RegAccess RegAccessGranted
Example from 32-bit PML
Hover over field values like Time, ResultCode, RegAccess, RegAccessGranted, RegDispos, and bytes of evdata and evresults in this example to see tooltips as they appear in viewer9. The tooltip of the first byte of a color patch tells the field name.
RegOpenKey opcode=2,0
ev=58
Time: | 2022-05-17 14:24:30.9881471 |
Duration: | 0.0000046 |
ResultCode: | SUCCESS |
Tid: | 3976 |
Path: | HKLM\System\CurrentControlSet\Control\DeviceClasses\{0850302a-b344-4fda-9be9-90576b8d46f0} |
RegAccess: | Query Value |
RegAccessGranted: | Query Value |
evdata[0-99] file offset 7953
0 | 5a 80 69 00 01 00 00 00 | Z.i..... |
8 | 48 4b 4c 4d 5c 53 79 73 | HKLM\Sys |
16 | 74 65 6d 5c 43 75 72 72 | tem\Curr |
24 | 65 6e 74 43 6f 6e 74 72 | entContr |
32 | 6f 6c 53 65 74 5c 43 6f | olSet\Co |
40 | 6e 74 72 6f 6c 5c 44 65 | ntrol\De |
48 | 76 69 63 65 43 6c 61 73 | viceClas |
56 | 73 65 73 5c 7b 30 38 35 | ses\.085 |
64 | 30 33 30 32 61 2d 62 33 | 0302a-b3 |
72 | 34 34 2d 34 66 64 61 2d | 44-4fda- |
80 | 39 62 65 39 2d 39 30 35 | 9be9-905 |
88 | 37 36 62 38 64 34 36 66 | 76b8d46f |
96 | 30 7d 6b 81 | 0.k. |
evresults[0-7] file offset 8055
0 | 01 00 00 00 00 00 00 00 | ........ |
Call Stack stacksize=45
StackAddress | mod | ModName | ModPath |
---|---|---|---|
0x816d40c8 | 71 | ntoskrnl.exe + 0x26b0c8 | C:\Windows\system32\ntoskrnl.exe |
0x8184cbfc | 71 | ntoskrnl.exe + 0x3e3bfc | C:\Windows\system32\ntoskrnl.exe |
0x817686dd | 71 | ntoskrnl.exe + 0x2ff6dd | C:\Windows\system32\ntoskrnl.exe |
0x816d1c3a | 71 | ntoskrnl.exe + 0x268c3a | C:\Windows\system32\ntoskrnl.exe |
0x816d0ed5 | 71 | ntoskrnl.exe + 0x267ed5 | C:\Windows\system32\ntoskrnl.exe |
0x816ccfba | 71 | ntoskrnl.exe + 0x263fba | C:\Windows\system32\ntoskrnl.exe |
0x8155ce2b | 71 | ntoskrnl.exe + 0xf3e2b | C:\Windows\system32\ntoskrnl.exe |
0x8154ad71 | 71 | ntoskrnl.exe + 0xe1d71 | C:\Windows\system32\ntoskrnl.exe |
0x816b3fbf | 71 | ntoskrnl.exe + 0x24afbf | C:\Windows\system32\ntoskrnl.exe |
0x816ace44 | 71 | ntoskrnl.exe + 0x243e44 | C:\Windows\system32\ntoskrnl.exe |
0x816acd2f | 71 | ntoskrnl.exe + 0x243d2f | C:\Windows\system32\ntoskrnl.exe |
0x816a922d | 71 | ntoskrnl.exe + 0x24022d | C:\Windows\system32\ntoskrnl.exe |
0x816a90f8 | 71 | ntoskrnl.exe + 0x2400f8 | C:\Windows\system32\ntoskrnl.exe |
0x816a9026 | 71 | ntoskrnl.exe + 0x240026 | C:\Windows\system32\ntoskrnl.exe |
0x816c1a73 | 71 | ntoskrnl.exe + 0x258a73 | C:\Windows\system32\ntoskrnl.exe |
0x816c196c | 71 | ntoskrnl.exe + 0x25896c | C:\Windows\system32\ntoskrnl.exe |
0x816c1426 | 71 | ntoskrnl.exe + 0x258426 | C:\Windows\system32\ntoskrnl.exe |
0x816c062f | 71 | ntoskrnl.exe + 0x25762f | C:\Windows\system32\ntoskrnl.exe |
0x816c0096 | 71 | ntoskrnl.exe + 0x257096 | C:\Windows\system32\ntoskrnl.exe |
0x816c004c | 71 | ntoskrnl.exe + 0x25704c | C:\Windows\system32\ntoskrnl.exe |
0x816c001c | 71 | ntoskrnl.exe + 0x25701c | C:\Windows\system32\ntoskrnl.exe |
0x81760dbf | 71 | ntoskrnl.exe + 0x2f7dbf | C:\Windows\system32\ntoskrnl.exe |
0x8173313e | 71 | ntoskrnl.exe + 0x2ca13e | C:\Windows\system32\ntoskrnl.exe |
0x8155ce2b | 71 | ntoskrnl.exe + 0xf3e2b | C:\Windows\system32\ntoskrnl.exe |
0x7714b65a | 57 | ntdll.dll + 0x6b65a | C:\Windows\SYSTEM32\ntdll.dll |
0x74b811a1 | 37 | KERNELBASE.dll + 0x111a1 | C:\Windows\system32\KERNELBASE.dll |
0x754240ca | 46 | KERNEL32.DLL + 0x40ca | C:\Windows\system32\KERNEL32.DLL |
0x74c55a14 | 67 | cfgmgr32.dll + 0x5a14 | C:\Windows\system32\CFGMGR32.dll |
0x74c55b04 | 67 | cfgmgr32.dll + 0x5b04 | C:\Windows\system32\CFGMGR32.dll |
0x74c5673e | 67 | cfgmgr32.dll + 0x673e | C:\Windows\system32\CFGMGR32.dll |
0x74c5667e | 67 | cfgmgr32.dll + 0x667e | C:\Windows\system32\CFGMGR32.dll |
0x73a5438c | 278 | DEVOBJ.dll + 0x438c | c:\windows\system32\DEVOBJ.dll |
0x6a0126a4 | 585 | BluetoothApis.dll + 0x26a4 | C:\Windows\System32\BluetoothApis.dll |
0x6a2eaa88 | 586 | bthprops.cpl + 0xaa88 | C:\Windows\System32\bthprops.cpl |
0x5b2243e5 | 707 | chrome.dll + 0x70b43e5 | C:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll |
0x5a8c77d3 | 707 | chrome.dll + 0x67577d3 | C:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll |
0x56f4b830 | 707 | chrome.dll + 0x2ddb830 | C:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll |
0x57623585 | 707 | chrome.dll + 0x34b3585 | C:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll |
0x57622e5c | 707 | chrome.dll + 0x34b2e5c | C:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll |
0x57621af8 | 707 | chrome.dll + 0x34b1af8 | C:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll |
0x544aa3d5 | 707 | chrome.dll + 0x33a3d5 | C:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll |
0x54992e91 | 707 | chrome.dll + 0x822e91 | C:\Program Files\Google\Chrome\Application\101.0.4951.67\chrome.dll |
0x754241a8 | 46 | KERNEL32.DLL + 0x41a8 | C:\Windows\system32\KERNEL32.DLL |
0x77132e31 | 57 | ntdll.dll + 0x52e31 | C:\Windows\SYSTEM32\ntdll.dll |
0x77132dff | 57 | ntdll.dll + 0x52dff | C:\Windows\SYSTEM32\ntdll.dll |
See also
Posted 4 Jul 2022 last updated 15 Nov 2022 As viewer9 is just starting out, discussion is invited via email. Please send questions and comments to forum@viewer9.com directly. Threads that might be valuable to other users will be posted as part of the documentation. Posted messages will not include your address or your full name, and might be shortened for brevity.
Copyright 2022, bryantlite, Inc.