Browsing anywhere in registry with PowerShell

Hello,

I think you all know that, but PowerShell gives us a nice way to explore registry :

GetRegistry

If you have a look at Get-PSDrive :

GetPSDrive

You’ll see that you have two drive dedicated to registry : HKCU and HKLM, for “Current User” and “Local Machine” respectively.

Now, let’s have a look at “RegEdit.exe” :

RegEdit

There are a lot more hives than just the two available in the PSDrive. You can mount a new PSDrive pointing to another hive :

New-PSDrive -Name HKUsers -PSProvider Registry -Root HKEY_USERS

New-PSDrive

Sure you can add it to your profile to create the PSDrive at each PowerShell.exe start, but, you have an alternative :

Registry2

You can force the use of the registry provider to browse anywhere in the registry.

Leave a Reply