Huge thanks to our Platinum Members Endace and LiveAction,
and our Silver Member Veeam, for supporting the Wireshark Foundation and project.

Display Filter Reference: Remote Registry Service

Protocol field name: winreg

Versions: 1.0.0 to 4.2.4

Back to Display Filter Reference

Field name Description Type Versions
winreg.access_maskAccess MaskUnsigned integer (32 bits)1.0.0 to 4.2.4
winreg.handleHandleByte sequence1.0.0 to 4.2.4
winreg.KeySecurityAttribute.data_sizeData SizeUnsigned integer (32 bits)1.0.0 to 4.2.4
winreg.KeySecurityAttribute.inheritInheritUnsigned integer (8 bits)1.0.0 to 4.2.4
winreg.KeySecurityAttribute.sec_dataSec DataLabel1.0.0 to 4.2.4
winreg.KeySecurityData.dataDataUnsigned integer (8 bits)1.0.0 to 4.2.4
winreg.KeySecurityData.lenLenUnsigned integer (32 bits)1.0.0 to 4.2.4
winreg.KeySecurityData.sizeSizeUnsigned integer (32 bits)1.0.0 to 4.2.4
winreg.opnumOperationUnsigned integer (16 bits)1.0.0 to 4.2.4
winreg.QueryMultipleValue.lengthLengthUnsigned integer (32 bits)1.0.0 to 1.10.14
winreg.QueryMultipleValue.nameNameCharacter string1.0.0 to 1.10.14
winreg.QueryMultipleValue.offsetOffsetUnsigned integer (32 bits)1.0.0 to 1.10.14
winreg.QueryMultipleValue.typeTypeUnsigned integer (32 bits)1.0.0 to 1.10.14
winreg.QueryMultipleValue.ve_typeVe TypeLabel1.12.0 to 4.2.4
winreg.QueryMultipleValue.ve_valuelenVe ValuelenUnsigned integer (32 bits)1.12.0 to 4.2.4
winreg.QueryMultipleValue.ve_valuenameVe ValuenameLabel1.12.0 to 4.2.4
winreg.QueryMultipleValue.ve_valueptrVe ValueptrUnsigned integer (32 bits)1.12.0 to 4.2.4
winreg.sdKeySecurityDataLabel1.0.0 to 4.2.4
winreg.sd.actual_sizeActual SizeUnsigned integer (32 bits)1.0.0 to 4.2.4
winreg.sd.max_sizeMax SizeUnsigned integer (32 bits)1.0.0 to 4.2.4
winreg.sd.offsetOffsetUnsigned integer (32 bits)1.0.0 to 4.2.4
winreg.system_nameSystem NameUnsigned integer (16 bits)1.0.0 to 4.2.4
winreg.werrorWindows ErrorUnsigned integer (32 bits)1.0.0 to 4.2.4
winreg.winreg_AbortSystemShutdown.serverServerUnsigned integer (16 bits)1.0.0 to 4.2.4
winreg.winreg_AccessMask.KEY_CREATE_SUB_KEYKEY CREATE SUB KEYBoolean1.0.0 to 4.2.4
winreg.winreg_AccessMask.KEY_ENUMERATE_SUB_KEYSKEY ENUMERATE SUB KEYSBoolean1.0.0 to 4.2.4
winreg.winreg_AccessMask.KEY_NOTIFYKEY NOTIFYBoolean1.0.0 to 4.2.4
winreg.winreg_AccessMask.KEY_QUERY_VALUEKEY QUERY VALUEBoolean1.0.0 to 4.2.4
winreg.winreg_AccessMask.KEY_SET_VALUEKEY SET VALUEBoolean1.0.0 to 4.2.4
winreg.winreg_AccessMask.KEY_WOW64_32KEYKEY WOW64 32KEYBoolean1.0.0 to 4.2.4
winreg.winreg_AccessMask.KEY_WOW64_64KEYKEY WOW64 64KEYBoolean1.0.0 to 4.2.4
winreg.winreg_CreateKey.action_takenAction TakenUnsigned integer (32 bits)1.0.0 to 4.2.4
winreg.winreg_CreateKey.keyclassKeyclassCharacter string1.0.0 to 4.2.4
winreg.winreg_CreateKey.nameNameCharacter string1.0.0 to 4.2.4
winreg.winreg_CreateKey.new_handleNew HandleByte sequence1.0.0 to 4.2.4
winreg.winreg_CreateKey.optionsOptionsUnsigned integer (32 bits)1.0.0 to 4.2.4
winreg.winreg_CreateKey.secdescSecdescLabel1.0.0 to 4.2.4
winreg.winreg_DeleteKey.keyKeyCharacter string1.0.0 to 4.2.4
winreg.winreg_DeleteKeyEx.access_maskAccess MaskUnsigned integer (32 bits)1.12.0 to 4.2.4
winreg.winreg_DeleteKeyEx.handleHandleByte sequence1.12.0 to 4.2.4
winreg.winreg_DeleteKeyEx.keyKeyCharacter string1.12.0 to 4.2.4
winreg.winreg_DeleteKeyEx.reservedReservedUnsigned integer (32 bits)1.12.0 to 4.2.4
winreg.winreg_DeleteValue.valueValueCharacter string1.0.0 to 4.2.4
winreg.winreg_EnumKey.enum_indexEnum IndexUnsigned integer (32 bits)1.0.0 to 4.2.4
winreg.winreg_EnumKey.keyclassKeyclassLabel1.0.0 to 4.2.4
winreg.winreg_EnumKey.last_changed_timeLast Changed TimeDate and time1.0.0 to 4.2.4
winreg.winreg_EnumKey.nameNameLabel1.0.0 to 4.2.4
winreg.winreg_EnumValue.enum_indexEnum IndexUnsigned integer (32 bits)1.0.0 to 4.2.4
winreg.winreg_EnumValue.lengthLengthUnsigned integer (32 bits)1.0.0 to 4.2.4
winreg.winreg_EnumValue.nameNameLabel1.0.0 to 4.2.4
winreg.winreg_EnumValue.sizeSizeUnsigned integer (32 bits)1.0.0 to 4.2.4
winreg.winreg_EnumValue.typeTypeLabel1.0.0 to 4.2.4
winreg.winreg_EnumValue.valueValueUnsigned integer (8 bits)1.0.0 to 4.2.4
winreg.winreg_GetKeySecurity.sec_infoSec InfoUnsigned integer (32 bits)1.0.0 to 4.2.4
winreg.winreg_GetVersion.versionVersionUnsigned integer (32 bits)1.0.0 to 4.2.4
winreg.winreg_InitiateSystemShutdown.do_rebootDo RebootUnsigned integer (8 bits)1.12.0 to 4.2.4
winreg.winreg_InitiateSystemShutdown.force_appsForce AppsUnsigned integer (8 bits)1.0.0 to 4.2.4
winreg.winreg_InitiateSystemShutdown.hostnameHostnameUnsigned integer (16 bits)1.0.0 to 4.2.4
winreg.winreg_InitiateSystemShutdown.messageMessageLabel1.0.0 to 4.2.4
winreg.winreg_InitiateSystemShutdown.rebootRebootUnsigned integer (8 bits)1.0.0 to 1.10.14
winreg.winreg_InitiateSystemShutdown.timeoutTimeoutUnsigned integer (32 bits)1.0.0 to 4.2.4
winreg.winreg_InitiateSystemShutdownEx.do_rebootDo RebootUnsigned integer (8 bits)1.12.0 to 4.2.4
winreg.winreg_InitiateSystemShutdownEx.force_appsForce AppsUnsigned integer (8 bits)1.0.0 to 4.2.4
winreg.winreg_InitiateSystemShutdownEx.hostnameHostnameUnsigned integer (16 bits)1.0.0 to 4.2.4
winreg.winreg_InitiateSystemShutdownEx.messageMessageLabel1.0.0 to 4.2.4
winreg.winreg_InitiateSystemShutdownEx.reasonReasonUnsigned integer (32 bits)1.0.0 to 4.2.4
winreg.winreg_InitiateSystemShutdownEx.rebootRebootUnsigned integer (8 bits)1.0.0 to 1.10.14
winreg.winreg_InitiateSystemShutdownEx.timeoutTimeoutUnsigned integer (32 bits)1.0.0 to 4.2.4
winreg.winreg_KeyOptions.REG_OPTION_BACKUP_RESTOREREG OPTION BACKUP RESTOREBoolean1.12.0 to 4.2.4
winreg.winreg_KeyOptions.REG_OPTION_VOLATILEREG OPTION VOLATILEBoolean1.12.0 to 4.2.4
winreg.winreg_LoadKey.filenameFilenameCharacter string1.0.0 to 4.2.4
winreg.winreg_LoadKey.keynameKeynameCharacter string1.0.0 to 4.2.4
winreg.winreg_NotifyChangeKeyValue.notify_filterNotify FilterUnsigned integer (32 bits)1.0.0 to 4.2.4
winreg.winreg_NotifyChangeKeyValue.string1String1Character string1.0.0 to 4.2.4
winreg.winreg_NotifyChangeKeyValue.string2String2Character string1.0.0 to 4.2.4
winreg.winreg_NotifyChangeKeyValue.unknownUnknownUnsigned integer (32 bits)1.0.0 to 4.2.4
winreg.winreg_NotifyChangeKeyValue.unknown2Unknown2Unsigned integer (32 bits)1.0.0 to 4.2.4
winreg.winreg_NotifyChangeKeyValue.watch_subtreeWatch SubtreeUnsigned integer (8 bits)1.0.0 to 4.2.4
winreg.winreg_NotifyChangeType.REG_NOTIFY_CHANGE_ATTRIBUTESREG NOTIFY CHANGE ATTRIBUTESBoolean1.12.0 to 4.2.4
winreg.winreg_NotifyChangeType.REG_NOTIFY_CHANGE_LAST_SETREG NOTIFY CHANGE LAST SETBoolean1.12.0 to 4.2.4
winreg.winreg_NotifyChangeType.REG_NOTIFY_CHANGE_NAMEREG NOTIFY CHANGE NAMEBoolean1.12.0 to 4.2.4
winreg.winreg_NotifyChangeType.REG_NOTIFY_CHANGE_SECURITYREG NOTIFY CHANGE SECURITYBoolean1.12.0 to 4.2.4
winreg.winreg_OpenHKCU.access_maskAccess MaskUnsigned integer (32 bits)1.0.0 to 4.2.4
winreg.winreg_OpenHKPD.access_maskAccess MaskUnsigned integer (32 bits)1.0.0 to 4.2.4
winreg.winreg_OpenKey.access_maskAccess MaskUnsigned integer (32 bits)1.0.0 to 4.2.4
winreg.winreg_OpenKey.keynameKeynameCharacter string1.0.0 to 4.2.4
winreg.winreg_OpenKey.optionsOptionsUnsigned integer (32 bits)1.12.0 to 4.2.4
winreg.winreg_OpenKey.parent_handleParent HandleByte sequence1.0.0 to 4.2.4
winreg.winreg_OpenKey.unknownUnknownUnsigned integer (32 bits)1.0.0 to 1.10.14
winreg.winreg_QueryInfoKey.classnameClassnameCharacter string1.0.0 to 4.2.4
winreg.winreg_QueryInfoKey.last_changed_timeLast Changed TimeDate and time1.0.0 to 4.2.4
winreg.winreg_QueryInfoKey.max_classlenMax ClasslenUnsigned integer (32 bits)1.12.0 to 4.2.4
winreg.winreg_QueryInfoKey.max_subkeylenMax SubkeylenUnsigned integer (32 bits)1.0.0 to 4.2.4
winreg.winreg_QueryInfoKey.max_subkeysizeMax SubkeysizeUnsigned integer (32 bits)1.0.0 to 1.10.14
winreg.winreg_QueryInfoKey.max_valbufsizeMax ValbufsizeUnsigned integer (32 bits)1.0.0 to 4.2.4
winreg.winreg_QueryInfoKey.max_valnamelenMax ValnamelenUnsigned integer (32 bits)1.0.0 to 4.2.4
winreg.winreg_QueryInfoKey.num_subkeysNum SubkeysUnsigned integer (32 bits)1.0.0 to 4.2.4
winreg.winreg_QueryInfoKey.num_valuesNum ValuesUnsigned integer (32 bits)1.0.0 to 4.2.4
winreg.winreg_QueryInfoKey.secdescsizeSecdescsizeUnsigned integer (32 bits)1.0.0 to 4.2.4
winreg.winreg_QueryMultipleValues.bufferBufferUnsigned integer (8 bits)1.0.0 to 4.2.4
winreg.winreg_QueryMultipleValues.buffer_sizeBuffer SizeUnsigned integer (32 bits)1.0.0 to 4.2.4
winreg.winreg_QueryMultipleValues.key_handleKey HandleByte sequence1.0.0 to 4.2.4
winreg.winreg_QueryMultipleValues.num_valuesNum ValuesUnsigned integer (32 bits)1.0.0 to 4.2.4
winreg.winreg_QueryMultipleValues.valuesValuesLabel1.0.0 to 1.10.14
winreg.winreg_QueryMultipleValues.values_inValues InLabel1.12.0 to 4.2.4
winreg.winreg_QueryMultipleValues.values_outValues OutLabel1.12.0 to 4.2.4
winreg.winreg_QueryMultipleValues2.bufferBufferUnsigned integer (8 bits)1.12.0 to 4.2.4
winreg.winreg_QueryMultipleValues2.key_handleKey HandleByte sequence1.12.0 to 4.2.4
winreg.winreg_QueryMultipleValues2.neededNeededUnsigned integer (32 bits)1.12.0 to 4.2.4
winreg.winreg_QueryMultipleValues2.num_valuesNum ValuesUnsigned integer (32 bits)1.12.0 to 4.2.4
winreg.winreg_QueryMultipleValues2.offeredOfferedUnsigned integer (32 bits)1.12.0 to 4.2.4
winreg.winreg_QueryMultipleValues2.values_inValues InLabel1.12.0 to 4.2.4
winreg.winreg_QueryMultipleValues2.values_outValues OutLabel1.12.0 to 4.2.4
winreg.winreg_QueryValue.dataDataUnsigned integer (8 bits)1.0.0 to 4.2.4
winreg.winreg_QueryValue.data_lengthData LengthUnsigned integer (32 bits)1.12.0 to 4.2.4
winreg.winreg_QueryValue.data_sizeData SizeUnsigned integer (32 bits)1.12.0 to 4.2.4
winreg.winreg_QueryValue.lengthLengthUnsigned integer (32 bits)1.0.0 to 1.10.14
winreg.winreg_QueryValue.sizeSizeUnsigned integer (32 bits)1.0.0 to 1.10.14
winreg.winreg_QueryValue.typeTypeLabel1.0.0 to 4.2.4
winreg.winreg_QueryValue.value_nameValue NameCharacter string1.0.0 to 4.2.4
winreg.winreg_ReplaceKey.handleHandleByte sequence1.12.0 to 4.2.4
winreg.winreg_ReplaceKey.new_fileNew FileCharacter string1.12.0 to 4.2.4
winreg.winreg_ReplaceKey.old_fileOld FileCharacter string1.12.0 to 4.2.4
winreg.winreg_ReplaceKey.subkeySubkeyCharacter string1.12.0 to 4.2.4
winreg.winreg_RestoreKey.filenameFilenameCharacter string1.0.0 to 4.2.4
winreg.winreg_RestoreKey.flagsFlagsUnsigned integer (32 bits)1.0.0 to 4.2.4
winreg.winreg_RestoreKey.handleHandleByte sequence1.0.0 to 4.2.4
winreg.winreg_RestoreKeyFlags.REG_FORCE_RESTOREREG FORCE RESTOREBoolean1.12.0 to 4.2.4
winreg.winreg_RestoreKeyFlags.REG_NO_LAZY_FLUSHREG NO LAZY FLUSHBoolean1.12.0 to 4.2.4
winreg.winreg_RestoreKeyFlags.REG_REFRESH_HIVEREG REFRESH HIVEBoolean1.12.0 to 4.2.4
winreg.winreg_RestoreKeyFlags.REG_WHOLE_HIVE_VOLATILEREG WHOLE HIVE VOLATILEBoolean1.12.0 to 4.2.4
winreg.winreg_SaveKey.filenameFilenameCharacter string1.0.0 to 4.2.4
winreg.winreg_SaveKey.handleHandleByte sequence1.0.0 to 4.2.4
winreg.winreg_SaveKey.sec_attribSec AttribLabel1.0.0 to 4.2.4
winreg.winreg_SaveKeyEx.filenameFilenameCharacter string1.12.0 to 4.2.4
winreg.winreg_SaveKeyEx.flagsFlagsUnsigned integer (32 bits)1.12.0 to 4.2.4
winreg.winreg_SaveKeyEx.handleHandleByte sequence1.12.0 to 4.2.4
winreg.winreg_SaveKeyEx.sec_attribSec AttribLabel1.12.0 to 4.2.4
winreg.winreg_SecBuf.inheritInheritUnsigned integer (8 bits)1.0.0 to 4.2.4
winreg.winreg_SecBuf.lengthLengthUnsigned integer (32 bits)1.0.0 to 4.2.4
winreg.winreg_SecBuf.sdSdLabel1.0.0 to 4.2.4
winreg.winreg_SetKeySecurity.access_maskAccess MaskUnsigned integer (32 bits)1.0.0 to 1.10.14
winreg.winreg_SetKeySecurity.sec_infoSec InfoUnsigned integer (32 bits)1.12.0 to 4.2.4
winreg.winreg_SetValue.dataDataUnsigned integer (8 bits)1.0.0 to 4.2.4
winreg.winreg_SetValue.nameNameCharacter string1.0.0 to 4.2.4
winreg.winreg_SetValue.sizeSizeUnsigned integer (32 bits)1.0.0 to 4.2.4
winreg.winreg_SetValue.typeTypeLabel1.0.0 to 4.2.4
winreg.winreg_String.nameNameCharacter string1.0.0 to 4.2.4
winreg.winreg_String.name_lenName LenUnsigned integer (16 bits)1.0.0 to 4.2.4
winreg.winreg_String.name_sizeName SizeUnsigned integer (16 bits)1.0.0 to 4.2.4
winreg.winreg_StringBuf.lengthLengthUnsigned integer (16 bits)1.0.0 to 4.2.4
winreg.winreg_StringBuf.nameNameUnsigned integer (16 bits)1.0.0 to 4.2.4
winreg.winreg_StringBuf.sizeSizeUnsigned integer (16 bits)1.0.0 to 4.2.4
winreg.winreg_UnLoadKey.handleHandleByte sequence1.12.0 to 4.2.4
winreg.winreg_UnLoadKey.subkeySubkeyCharacter string1.12.0 to 4.2.4
winreg.winreg_ValNameBuf.lengthLengthUnsigned integer (16 bits)1.12.0 to 4.2.4
winreg.winreg_ValNameBuf.nameNameUnsigned integer (16 bits)1.12.0 to 4.2.4
winreg.winreg_ValNameBuf.sizeSizeUnsigned integer (16 bits)1.12.0 to 4.2.4