offlineUpgrade %WINDIR%\offlineUpgrade * [*] * [*] HKLM\SYSTEM\CurrentControlSet\Control\Lsa [Security Packages] HKLM\SYSTEM\CurrentControlSet\Control\Lsa [Security Packages] HKLM\SYSTEM\CurrentControlSet\Services\NDIS\IfTypes\* [*] %WINDIR% [WindowsUpdate.log] %WINDIR%\SoftwareDistribution\* [*] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\* [*] HKLM\SOFTWARE\Microsoft\WindowsUpdate\UpdatePolicy\PolicyState [TemporaryEnterpriseFeatureControlState] HKLM\SYSTEM\CurrentControlSet\Control\FeatureManagement\Policies [TemporaryEnterpriseFeatureControlState_Mirrored] %WINDIR%\SoftwareDistribution\DataStore\* [*] %WINDIR%\SoftwareDistribution\DeliveryOptimization\* [*] %WINDIR%\SoftwareDistribution\Download\* [*] %WINDIR%\SoftwareDistribution\ScanFile\* [*] %WINDIR%\SoftwareDistribution\SelfUpdate\* [*] %WINDIR%\SoftwareDistribution\WebSetup\* [*] %WINDIR%\SoftwareDistribution\WuRedir\* [*] %WINDIR%\SoftwareDistribution\Featured\* [*] %WINDIR%\SoftwareDistribution\PostRebootEventCache.V2\* [*] %WINDIR%\SoftwareDistribution\DeploymentStack\* [*] %WINDIR%\SoftwareDistribution [ReportingEvents.log] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdateSysprepInProgress\* [*] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Setup\* [*] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update [SetupWizardLaunchTime] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update [FirstDetectionFailureTime] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update [BalloonType] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update [BalloonTime] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update [ScheduledInstallDate] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update [ScheduledInstallDay] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update [ScheduledInstallTime] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update [ShowUnableToDetectUI] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update [OfflineDetectionPending] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update [UnableToDetectTime] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update [DownloadExpirationTime] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update [NextDetectionTime] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update [NextFeaturedUpdatesNotificationTime] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update [FeaturedUpdatesNotificationSeqNumGenTime] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update [FeaturedUpdatesNotificationSeqNum] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\* [*] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\RebootRequired\* [*] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\UAS\* [*] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Volatile\* [*] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\UXFirmwareInstallsAllowed\* [*] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\AutoFirmwareInstallsAllowedAtShutdown\* [*] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\RequestedAppCategories\* [*] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Orchestrator [UpdateRebootTime] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Orchestrator [FlightRebootTime] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Orchestrator [OobeCompleteTimeStamp] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Orchestrator [OSSwapDetectionInitialized] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Reporting\RebootWatch\* [*] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Reporting\RebootNotCompleted\* [*] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Reporting\RebootCompletionReported\* [*] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Reporting\DontExpirePolledEvents\* [*] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Reporting\EventCache.v2\* [*] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update [ResetAU] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update [SelfUpdateTime] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate [UpdateId] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Orchestrator [NextRefreshTime] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Orchestrator [SettingsETag] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Orchestrator\Lus [*] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Orchestrator\Settings [*] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Orchestrator\UScheduler\* [*] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate [UseDeploymentProvider] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Orchestrator [UDPMode] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Orchestrator\ActiveUpdateSessions\* [*] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Orchestrator\EnterpriseAttribution\* [*] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Orchestrator\InstallAtShutdown\* [*] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Orchestrator\RebootRequired\* [*] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\CommitRequired\* [*] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\DeploymentCallbackInfo\* [*] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\DeploymentStack\* [*] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Orchestrator [ScanBeforeInitialLogonCompleted] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\StickyUpdates\* [*] %WINDIR% [WindowsUpdate.log] %WINDIR%\SoftwareDistribution\* [*] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\* [*] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Notifications [*] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Notifications [*] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Notifications\* [*] HKLM\SYSTEM\CurrentControlSet\Control\TimeZoneInformation\* [*] HKLM\SYSTEM\CurrentControlSet\Control\TimeZoneInformation [ActiveTimeBias] HKLM\SYSTEM\CurrentControlSet\Control\TimeZoneInformation\* [*] HKLM\SYSTEM\CurrentControlSet\Control\TimeZoneInformation\* [*] HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\$ [NetLuidIndex] HKLM\SYSTEM\CurrentControlSet\Control\Class\{6BDD1FC5-810F-11D0-BEC7-08002BE2092F}\$ [NetLuidIndex] HKLM\SYSTEM\CurrentControlSet\Control\Network\{4D36E972-E325-11CE-BFC1-08002bE10318}\{* [*] HKLM\SYSTEM\CurrentControlSet\Control\Nsi\{eb004a11-9b1a-11d4-9123-0050047759bc}\10\* [*] HKLM\SYSTEM\CurrentControlSet\Control\Nsi\{eb004a11-9b1a-11d4-9123-0050047759bc}\7\* [*] HKLM\SYSTEM\CurrentControlSet\Control\Nsi\{eb004a11-9b1a-11d4-9123-0050047759bc}\6\* [*] HKLM\SYSTEM\CurrentControlSet\Services\NDIS\IfTypes\$ [IfType] HKLM\SYSTEM\CurrentControlSet\Services\NDIS\IfTypes\$ [IfUsedNetLuidIndices] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Orchestrator [OSMigrationDetection] Dword 01000000 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Orchestrator [OSMigrationDetection] MigXmlHelper.IsOSEarlierThan("NT","6.0.0.0") HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\* [*] HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\WinRM\* [*] HKLM\SYSTEM\CurrentControlSet\Services\EventLog\System\WinRM\* [*] HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Security\AD FS 2.0 Auditing\*[*] HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\ADAM* HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\$ [File] HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\* [*] HKLM\SYSTEM\CurrentControlSet\Services\Eventlog [*] HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\$ [CustomSD] HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\$ [Isolation] HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\$ [Retention] HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\$ [AutoBackupLogFiles] HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\$ [MaxSize] MigXmlHelper.IsOSEarlierThan("NT","6.0.0.0") HKLM\Software\Microsoft\Windows\CurrentVersion\winevt\* [*] HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\* [*] HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Security\AD FS 2.0 Auditing\*[*] HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\ADAM* HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{832d43c6-2e88-4be7-a4d1-61fc2430ff07}\* [*] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{d6795c62-6f24-4363-99ce-2ff3f4b1faba}\* [*] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{f863cf1c-c759-4dc0-98bb-81a109974cdf}\* [*] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{fb5e81f8-9a5c-4c9e-8144-6b9123e078df}\* [*] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{d2dd58ba-3ed4-4d5a-9987-af473bb6d0b0}\* [*] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{1be39648-5678-4fae-839b-10da2c4cf234}\* [*] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{cd75048f-1233-4f58-b9ed-98ba2097ac7e}\* [*] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{4153360c-6259-4e56-900c-818532b7897d}\* [*] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{5b33145c-1c66-49f3-b4ca-f563c165f2c0}\* [*] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{13e8b4f7-4d1c-4f65-95a2-39c6b26a3012}\* [*] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{986329a0-a1d5-46cf-8801-595d646c271f}\* [*] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{1fd7c1d2-d037-4620-8d29-b2c7e5fcc13a}\* [*] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{560b2594-7530-4c77-8998-f067ae1e2918}\* [*] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{a58d520f-c444-4982-bb61-8db7f0a5f217}\* [*] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{4d5ae6a1-c7c8-4e6d-b840-4d8080b42e1b}\* [*] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{eea178e3-e9d4-41ca-bb56-cede1a476629}\* [*] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{4b3efc0a-e514-4022-bd50-532620d2d9fb}\* [*] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{67beaf60-484b-4078-a99b-95cf827c553b}\* [*] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{2129b945-09ed-4965-820e-032243a31578}\* [*] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{e4c60dfa-ecc5-4889-b406-e9ddd38463c8}\* [*] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{565bbeca-5b04-49bb-81c6-3e21527fcc8a}\* [*] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{e98754d0-883b-11db-b606-0800200c9a66}\* [*] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{95353826-4fbe-41d4-9c42-f521c6e86360}\* [*] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{bc2eeeec-b77a-4a52-b6a4-dffb1b1370cb}\* [*] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{57e0b31d-de8c-4181-bcd1-f70e880b49fc}\* [*] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{8c9dd1ad-e6e5-4b07-b455-684a9d879900}\* [*] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{e7ef96be-969f-414f-97d7-3ddb7b558ccc}\* [*] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{98583af0-fc93-4e71-96d5-9f8da716c6b8}\* [*] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{92ae46d7-6d9c-4727-9ed5-e49af9c24cbf}\* [*] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{01979c6a-42fa-414c-b8aa-eee2c8202018}\* [*] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{3df0c2c1-5a04-4966-9790-df6ef0ccde9c}\* [*] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{b43979bf-6596-4d15-944f-cd89b2b935ca}\* [*] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{788fda79-b68a-40df-b409-8778a3fa6edd}\* [*] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\winevt\Channels\Microsoft-Windows-DxpTaskRingtone/Analytic\* [*] HKLM\Software\Microsoft\Windows\CurrentVersion\winevt\channels\Microsoft-Windows-MeetingSpace/Operational [*] HKLM\Software\Microsoft\Windows\CurrentVersion\winevt\channels\Microsoft-Windows-Security-Licensing-SLC/Perf [*] HKLM\Software\Microsoft\Windows\CurrentVersion\winevt\channels\Microsoft-Windows-TerminalServices-Gateway/* [*] HKLM\Software\Microsoft\Windows\CurrentVersion\winevt\channels\Microsoft-Windows-Diagnosis-MSDT* [*] HKLM\Software\Microsoft\Windows\CurrentVersion\winevt\channels\Microsoft-Windows-PrintSpooler* [*] HKLM\Software\Microsoft\Windows\CurrentVersion\winevt\channels\Microsoft-Windows-Eventlog-ForwardPlugin/Debug [*] HKLM\Software\Microsoft\Windows\CurrentVersion\winevt\channels\Microsoft-Windows-OfflineFiles* [*] HKLM\Software\Microsoft\Windows\CurrentVersion\winevt\Channels\Microsoft-Windows-EDP-Application-Learning/Operational [*] HKLM\Software\Microsoft\Windows\CurrentVersion\winevt\* [*] HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\* [*] HKLM\SYSTEM\CurrentControlSet\Services\Eventlog [*] HKLM\Software\Microsoft\Windows\CurrentVersion\winevt\channels\$ [File] HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\$ [File] HKLM\Software\Microsoft\Windows\CurrentVersion\winevt [*] HKLM\Software\Microsoft\Windows\CurrentVersion\winevt\channels\$ [*] HKLM\Software\Microsoft\Windows\CurrentVersion\winevt\filters\* [*] HKLM\SYSTEM\CurrentControlSet\Control\WMI\Autologger\Diagtrack-Listener\* [*] HKLM\SYSTEM\CurrentControlSet\Control\WMI\Autologger\Diagtrack-Listener\* [*] HKLM\SYSTEM\CurrentControlSet\Services\partmgr\Parameters [SanPolicy] HKLM\SYSTEM\CurrentControlSet\Services\mountmgr [NoAutoMount] MigXmlHelper.DoesObjectExist("Registry", "HKLM\SYSTEM\CurrentControlSet\Services\partmgr\Parameters [SanPolicy]") HKLM\SYSTEM\CurrentControlSet\Services\mountmgr [NoAutoMount] HKLM\SYSTEM\CurrentControlSet\Services\mountmgr [NoAutoMount] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Print\PrinterMigration\* [*] HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors\3D Port\* [*] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Print\Printers\* [*] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Print\Printers\*[*] HKLM\SYSTEM\Setup\Upgrade\* [*] HKLM\SYSTEM\Setup\Upgrade\PnP\CurrentControlSet\Services\*\State\* [*] HKLM\SYSTEM\Setup\Upgrade\PnP\CurrentControlSet\Services\*\SharedState\* [*] HKLM\SYSTEM\Setup\Upgrade\Appx\* [*] DCRoleOfflineUpgrade %WINDIR%\DCRoleOfflineUpgrade MigXmlHelper.DoesStringContentEqual("Registry", "HKLM\SYSTEM\CurrentControlSet\control\ProductOptions [ProductType]", "LanManNT") HKLM\SYSTEM\CurrentControlSet\Services\NTDS [DirectoryServiceExtPt] ExpandString %SystemRoot%\system32\ntdsa.dll HKLM\SYSTEM\CurrentControlSet\Services\NTDS [LsaDbExtPt] ExpandString %SystemRoot%\system32\lsadb.dll HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Parameters [ServiceDll] ExpandString %SystemRoot%\system32\ntdsa.dll HKLM\SYSTEM\CurrentControlSet\Services\NTDS [DirectoryServiceExtPt] HKLM\SYSTEM\CurrentControlSet\Services\NTDS [LsaDbExtPt] HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Parameters [ServiceDll] HKLM\System\CurrentControlSet\Services\NTDS [Start] Dword 02000000 HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Diagnostics\* [*] HKLM\SYSTEM\CurrentControlSet\Services\NTDS\rid\* [*] HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Parameters\* [*] HKLM\SYSTEM\CurrentControlSet\Services\NTDS\RID Values\* [*] HKLM\SYSTEM\CurrentControlSet\control\ProductOptions [ProductType] HKLM\SYSTEM\CurrentControlSet\Services\NetLogon\Parameters [SysVol] HKLM\SOFTWARE\Microsoft\NTDS\* [*] HKLM\System\CurrentControlSet\Services\NTDS [Start] MigXmlHelper.DoesStringContentContain("Registry", "HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Parameters [DSA Working Directory]","%SystemRoot%") MigXmlHelper.DoesStringContentContain("Registry", "HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Parameters [DSA Working Directory]","%ProgramFiles%") MigXmlHelper.DoesStringContentContain("Registry", "HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Parameters [DSA Working Directory]","%SystemDrive%\Program Files") MigXmlHelper.DoesStringContentContain("Registry", "HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Parameters [DSA Working Directory]","%ProgramFiles(x86)%") MigXmlHelper.DoesStringContentContain("Registry", "HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Parameters [DSA Working Directory]","%SystemDrive%\build") MigXmlHelper.DoesStringContentContain("Registry", "HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Parameters [DSA Working Directory]","%SystemDrive%\InstalledRepository") MigXmlHelper.DoesStringContentContain("Registry", "HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Parameters [DSA Working Directory]","%ProgramData%") MigXmlHelper.DoesStringContentContain("Registry", "HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Parameters [DSA Working Directory]","%SystemDrive%\Documents and Settings") MigXmlHelper.DoesEnvironmentVariableEqual("MIG_DISABLE_USER_PROCESSING", "TRUE") MigXmlHelper.DoesEnvironmentVariableEqual("MIG_DISABLE_USER_PROCESSING", "Yes") MigXmlHelper.DoesEnvironmentVariableEqual("MIG_DISABLE_USER_PROCESSING", "1") MigXmlHelper.DoesStringContentContain("Registry", "HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Parameters [DSA Working Directory]","%ProfilesFolder%") %DSA_WORKING_DIR%\* [*] MigXmlHelper.DoesStringContentContain("Registry", "HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Parameters [Database log files path]","%SystemRoot%") MigXmlHelper.DoesStringContentContain("Registry", "HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Parameters [Database log files path]","%ProgramFiles%") MigXmlHelper.DoesStringContentContain("Registry", "HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Parameters [Database log files path]","%SystemDrive%\Program Files") MigXmlHelper.DoesStringContentContain("Registry", "HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Parameters [Database log files path]","%ProgramFiles(x86)%") MigXmlHelper.DoesStringContentContain("Registry", "HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Parameters [Database log files path]","%SystemDrive%\build") MigXmlHelper.DoesStringContentContain("Registry", "HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Parameters [Database log files path]","%SystemDrive%\InstalledRepository") MigXmlHelper.DoesStringContentContain("Registry", "HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Parameters [Database log files path]","%ProgramData%") MigXmlHelper.DoesStringContentContain("Registry", "HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Parameters [Database log files path]","%SystemDrive%\Documents and Settings") MigXmlHelper.DoesEnvironmentVariableEqual("MIG_DISABLE_USER_PROCESSING", "TRUE") MigXmlHelper.DoesEnvironmentVariableEqual("MIG_DISABLE_USER_PROCESSING", "Yes") MigXmlHelper.DoesEnvironmentVariableEqual("MIG_DISABLE_USER_PROCESSING", "1") MigXmlHelper.DoesStringContentContain("Registry", "HKLM\SYSTEM\CurrentControlSet\Services\NTDS\Parameters [Database log files path]","%ProfilesFolder%") %DATABASE_LOG_FILES_PATH%\* [*] DiagTrack HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack [DiagTrackDbVersion] %ProgramData%\Microsoft\Diagnosis [*.rbs] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack [DiagTrackDbVersion] %ProgramData%\Microsoft\Diagnosis [*.rbs] Microsoft-Windows-AppX-Deployment-Server MigXmlHelper.IsOSEarlierThan("NT", "10.0.14392") %ProgramData%\Microsoft\Windows\AppRepository [StateRepository-Machine*] %ProgramData%\Microsoft\Windows\AppRepository [StateRepository-Machine*] MigXmlHelper.IsOSEarlierThan("NT", "10.0.14392") %ProgramData%\Microsoft\Windows\AppRepository [StateRepository-*] %ProgramData%\Microsoft\Windows\AppRepository [StateRepository-*] HKLM\SYSTEM\Setup\Upgrade\Appx\* [*] %PROGRAMFILES%\WindowsApps\$ Microsoft-OneCore-Bluetooth-Gatt HKLM\Software\Microsoft\Windows\CurrentVersion\Bluetooth\* [*] HKLM\Software\Microsoft\Windows\CurrentVersion\Bluetooth\Gatt\0\0\* [*] HKLM\Software\Microsoft\Windows\CurrentVersion\Bluetooth\Gatt\ManifestService\* [*] HKLM\Software\Microsoft\Windows\CurrentVersion\Bluetooth\* Microsoft-Windows-Graphics-Display-DisplayEnhancementService HKLM\System\CurrentControlSet\Services\DisplayEnhancementService\State\* [*] HKLM\System\CurrentControlSet\Services\DisplayEnhancementService\State\* Microsoft-Windows-CommonLog MigXmlHelper.DoesObjectExist("Registry", "HKLM\System\CurrentControlSet\Services\CLFS\Authentication [Mode]") HKLM\System\CurrentControlSet\Services\CLFS\Authentication [Mode] Dword 01000000 HKLM\System\CurrentControlSet\Services\CLFS\Authentication [*] HKLM\System\CurrentControlSet\Services\CLFS\Authentication [*]