filerenameop

$ target-query <path/to/target> -f filerenameop
Details

Module

dissect.target.plugins.os.windows.generic.GenericPlugin

Output

records

Module documentation

Generic Windows plugin.

Provides Windows operating system plugins too small to fit in a separate plugin.

Function documentation

Return all pending file rename operations.

The PendingFileRenameOperations registry key value contains information about files that will be renamed on reboot. Can be used to hunt for malicious binaries.

References: