Interfaces Registry Key
The Interfaces registry key will provide information regarding the systems attached network interface adatpers, such as IP address and MAC address.
Analysis Value
π₯οΈSystem EnumerationOperating System Availability
Windows 11
β
Server 2019
β
Windows 10
β
Server 2016
β
Windows 8
β
Server 2012
β
Windows 7
β
Server 2008
β
Windows Vista
β
Server 2003
β
Windows XP
β
Artifact Location(s)
File:
%SystemRoot%\System32\config\SYSTEMKey:
SYSTEM\{CURRENT_CONTROL_SET}\Services\Tcpip\Parameters\Interfaces\{INTERFACE_GUID}
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{INTERFACE_GUID}
Artifact Parsers
RegistryExplorer (Eric Zimmerman)
Artifact Interpretation
Each interface will have its own dedicated registry key, and may contain the following values of interest:
DhcpDomain
REG_SZ
DHCP option 15 - the domain name of the endpoints FQDN
DhcpIPAddress
REG_SZ
The DHCP - provided IP address of the endpoint
DhcpServer
REG_SZ
The DHCP server that provided the endpoint its network configuration
EnableDHCP
REG_DWORD
0x0 if DHCP is disabled and 0x1 if DHCP is enabled
LeaseObtainedTime
REG_DWORD
FILETIME timestamp of when the endpoint received a DHCP lease
LeaseTerminatesTime
REG_DWORD
FILETIME timestamp of when the endpoint's DHCP lease expires
Example
Correlating with the NetworkCards registry key:
This example was produced on Windows 10, Version 10.0.19044 Build 19044
Last updated