• Manufacturer: Microsoft
  • Version: 13.98
  • Website: https://technet.microsoft.com/en-us/sysinternals/bb963902.aspx

Description

Autoruns reports Explorer shell extensions, toolbars, browser helper objects, Winlogon notifications, auto-start services, etc.at is provided as part of the Windows Sysinternals suite of tools. It collects system information while running in the background and supports storing it in the Windows Event Log.

Data Model Coverage

registry

  data fqdn hive hostname image_path key new_content pid type user value
add        
key_edit      
remove                      
value_edit      

service

  command_line exe fqdn hostname image_path name pid ppid uid user
create        
delete        
pause                    
start                    
stop                    

file

  company content creation_time extension file_name file_path fqdn gid group hostname image_path link_target md5_hash mime_type mode owner owner_uid pid ppid previous_creation_time sha1_hash sha256_hash signature_valid signer uid user
acl_modify                                                    
create                              
delete                                                    
modify                              
read                                                    
timestomp                                                    
write                                                    

Analytic Coverage