Skip to content

RegShot

What RegShot does

Guided SUSA tool journey

RegShot supports Registry analysis. In this guide, you will use it to compare controlled before-and-after snapshots and explain one Registry change. The procedure and screenshots provide the practical reference; the surrounding context explains what to record and how to judge the result.

Tool guide at a glance

Investigation task

Compare controlled before-and-after snapshots and explain one Registry change.

Starting material

Copied Windows Registry hives with their available transaction logs and profile context.

Successful outcome

A key or value finding linked to its hive, user or system context, parser, and limitations.

Evidence and safety

Never edit source hives. Keep user SID, control-set, and transaction-log context attached. Record the input identifier, tool version, relevant commands or settings, time and time zone, output location, and any errors or limitations as you work.

Choose your journey

How the labs complement this guide

The Interactive Lab is a safe browser simulation for practising the workflow and validation logic. The Full Lab is an independent exercise for an isolated, authorised environment. Confirm the installed tool version and expected output before relying on either exercise in a real case.

Accessing RegShot in SUSA

Regshot is a lightweight utility used to take snapshots of the Windows Registry and compare them to identify changes.

Create the first snapshot before a controlled action and the second immediately afterwards, using the same scope and output format. The comparison shows changes between those two states; it does not identify the responsible process or user, so corroborate relevant entries with process, file-system and event evidence.

Download RegShot-x64-Unicode.exe. Click the download icon to download the executable.

Screenshot: Download RegShot-x64-Unicode.exe. Click the download icon to download the executable

Move the downloaded executable to C:\Tools\RegShot. Open it and confirm that RegShot starts without an error.

When prompted by the User Account Control, select Yes.

Screenshot: When prompted by the User Account Control, select Yes

Screenshot: When prompted by the User Account Control, select Yes