| Plugin | Hive | What it gives |
|---|---|---|
| defender | SOFTWARE | Defender config |
| disableeventlog | SYSTEM | Event log tampering |
| disableuserassist | NTUSER | UserAssist disabled |
| cred | SYSTEM | WDigest |
| uac | SOFTWARE | UAC config |
| uacbypass | SOFTWARE / USRCLASS | Bypass traces |
| fileless | ALL | Fileless indicators |
| findexes | ALL | MZ blobs in registry |
BLUE TEAM / DFI / ARTEFACT / WINDOWS / REGISTRY / RegRipper