Regedit.exe

Used by Windows to manipulate registry

Paths

  • C:\Windows\regedit.exe

Commands

ADS

Export the target Registry key to the specified .REG file.

Use case: Hide registry data in alternate data stream

Privileges: User

regedit /E {PATH_ABSOLUTE}:regfile.reg HKEY_CURRENT_USER\MyCustomRegKey

ADS

Import the target .REG file into the Registry.

Use case: Import hidden registry data from alternate data stream

Privileges: User

regedit {PATH_ABSOLUTE}:regfile.reg

Detection

Resources