[no000017f] How to monitor registry modifications

Source: Internet
Author: User

Today we will show you how to use one of our favorite tools Proc Mon , when you change PC view the edited registry key when you set the Group Policy setting on the

Use Proc Mon to view registry settings modified by a Group Policy object

The first thing you need to do is Sys Internals website gets a copy of Proc Mon .

then, you need to unzip the folder and run Procmon.exe file.

when Proc Mon When you open, you need to add the following criteria:

the process name is mmc.exe then contains

and then click " Add " button.

To get only the changed registry entries, we need to add another:

Action is RegSetValue then include

and then click again " Add " button.

After you add two rules, you can continue and click " Determine " .

Now go to open the Group Policy setting you want to edit.

before you actually change the settings, switch back to Proc Mon and clear the log.

then go to and change GPO and click " Application " .

If you switch to Proc Mon , you will see that you have a registry key. Right-click it and select Jump to ... from the context menu . options.

this will start Regedit and take you to the exact key after the change

That's all they are.

How to see which Registry Settings a Group Policy Object modifies

Today we are going to show do you have a favorite tools, Proc Mon, to see which registry keys is edited when A Group Policy setting on your PC.

Using Proc Mon to see which Registry Settings a Group Policy Object modifies

The first thing you'll want to does is go and get yourself a copy of Proc Mon from the Sys Internals website.

Then you'll need to extract the folder and run the Procmon.exe file.

When Proc Mon opens, you'll need to add a condition as follows:

Process Name is mmc.exe then Include

Then click the Add button.

To get only the registry keys is changed, we need add another one:

Operation is RegSetValue then Include

Then again click the Add button.

Once the been added, you can go ahead and click OK.

Now go and open the Group Policy setting this wish to edit.

Before you actually change the setting, switch back through to Proc Mon and clear the log.

Then go and change the GPO and click Apply.

IF you switch through to Proc Mon, you'll see that there's a registry key (s) there. Right-click on the IT and select the jump to ... option from the context menu.

That'll fire up Regedit and take you to the exact key which was modified

That's all there are to it guys.

[no000017f] How to monitor registry modifications

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.