hivelist Audit

Prev Next

Collects Windows registry hives used in a registry listing audit. This includes hives that can only be acquired in raw mode, such as the Security Account Manager (SAM) hive.

This audit was formerly known as the w32hivelist audit.

Supported Platforms

Windows

Input Parameters

The following input parameters are available for this audit.

Prevent Hibernation

Details

Values

Description

Platform

Windows

Windows environments

Format

Bool

Valid values are Boolean values.

Required?

no

This parameter is not required.

Repeatable?

no

This parameter can be specified only once per audit request. It cannot be repeated.

Valid Values

Use Boolean values to indicate whether to prevent the host endpoint from entering hibernation while this audit is executed.