Solved

Use Powershell Script to Recursively Search Remote Registry

Posted on 2011-03-18
3
2,605 Views
Last Modified: 2012-05-11
I have a script that I can use to remotely search a local registry for a subkey and get it's value.

I need to do a similar script that will search remote computers once provided with the computer name.


I read that I need to use .Net for remote access but it doesn't seem that it'll work


$values = ''
$MachineName = hostname                                                                            

$key = Get-ChildItem registry::HKU -recurse	-include Lotus -ErrorAction silentlycontinue | Select-Object -first 1 
$sub = Get-ChildItem Registry::$key -recurse -include Installer

$values = Get-ItemProperty $sub.PSPath
$values.PROGDIR

Open in new window

0
Comment
Question by:MaxZetoX
3 Comments
 
LVL 16

Accepted Solution

by:
Learnctx earned 500 total points
ID: 35170710
Done this one up quickly, maybe not the nicest script you'll ever use :) But for this example, it will search all subkeys below SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318} for a value of DeviceInstanceID and return the data stored in that value.
Function Reg-Query ($target, $key)
{
	try
	{
        $reg = [Microsoft.Win32.RegistryKey]::OpenRemoteBaseKey("LocalMachine", $target)
        foreach ($sub in $reg.OpenSubKey($key).GetSubKeyNames())
        {
            $subkey = $reg.OpenSubKey("$($key)\$($sub)")
            foreach ($value in $subkey.GetValueNames())
            {
                if ($value -eq $targetvalue)
                {
                    $subkey.GetValue($value)
                    break
                }
            }
            Reg-Query -target $computer -key "$($key)\$($sub)"
        }
	} catch [System.Security.SecurityException] {
        "ACCESS DENIED: $($key)"
	} catch {
        $_.Exception.Message
    }
}

cls
$computer = "computernamehere"
$rootkey = "SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}"
$targetvalue = "DeviceInstanceID"
Reg-Query -computer $target -key $rootkey

Open in new window

0
 
LVL 70

Expert Comment

by:Chris Dent
ID: 35687986
This question has been classified as abandoned and is closed as part of the Cleanup Program. See the recommendation for more details.
0

Featured Post

Threat Intelligence Starter Resources

Integrating threat intelligence can be challenging, and not all companies are ready. These resources can help you build awareness and prepare for defense.

Join & Write a Comment

Hi all.   The other day I had to change the passwords for a bunch of users on the fly. Because they were so many, I decided to do it in an automated way and I would like to share it with you all.   If you are not doing it directly in a Domain Co…
A procedure for exporting installed hotfix details of remote computers using powershell
Excel styles will make formatting consistent and let you apply and change formatting faster. In this tutorial, you'll learn how to use Excel's built-in styles, how to modify styles, and how to create your own. You'll also learn how to use your custo…
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…

707 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

13 Experts available now in Live!

Get 1:1 Help Now