Ask Leo: How do I monitor what changes in my registry?

monitor changes to registry

How do I monitor what changes in my registry?

By Leo Notenboom

All I want to do is: make a copy of the registry, install a program, make another copy of the registry, and compare to see the changes.

Monitoring what happens in the registry can sometimes be a very useful thing.

I think that in general, you’ll be very surprised at how much activity happens in the registry, particularly for an install.

There are a couple of ways to do what you’re suggesting: comparing before and after snapshots of the registry and monitoring the changes as they happen.

I’ll discuss both.

Comparing Registry Snapshots

Before you run the installation program, run the Registry Editor. Use the Run item on the Start menu, or press the Windows key plus the letter R, and then type in “regedit” and click OK.

monitor changes in registry

Make sure that the top-level item – “Computer” – is selected as shown above.. Just click it once.

Now click File, and then Export…

monitor changes in registry 2

Article Continued Here

This post is excerpted with permission from Leo Notenboom.

Stop Responding to Threats.
Prevent Them.

Want to get monthly tips & tricks?

Subscribe to our newsletter to get cybersecurity tips & tricks and stay up to date with the constantly evolving world of cybersecurity.

Related Articles