Regini.exe

Used to manipulate the registry

Paths

  • C:\Windows\System32\regini.exe
  • C:\Windows\SysWOW64\regini.exe

Commands

ADS

Write registry keys from data inside the Alternate data stream.

Use case: Write to registry

Privileges: User

regini.exe {PATH}:hidden.ini

Detection

Resources