UpgradeFramework MigXmlHelper.IsMigrationScope("FrameworkBasic") HKLM\SYSTEM\MountedDevices [\DosDevices\*] HKLM\SYSTEM\CurrentControlSet\Services\i8042prt\Parameters\*[*] HKLM\SYSTEM\CurrentControlSet\Control\FVEAutoUnlock\* [*] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion [*] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion [*] MigXmlHelper.IsMigrationScope("FrameworkFull") * [*] * [*] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion [*] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion [*] MigXmlHelper.IsOSLaterThan("NT","6.2.0.0") HKU\.DEFAULT\Software\Microsoft\IdentityCRL\StoredIdentities\*[*] HKU\.DEFAULT\Software\Microsoft\IdentityCRL\DPAPICloudKeyVersionMappings\*[*] %ProgramData%\Microsoft\Windows\SystemData\S-$\ReadOnly\LockScreen\*[*] %ProgramData%\Microsoft\Windows\SystemData\S-$\ReadOnly\PicturePassword\*[*] %ProgramData%\Microsoft\Vault\*[*] %System32%\config\systemprofile\AppData\Local\Microsoft\Vault\*[*] %System32%\config\systemprofile\AppData\Roaming\Microsoft\Vault\*[*] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\LogonUI\PINLogonEnrollment\*[*] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\LogonUI\PicturePassword\*[*] %ProgramData%\Microsoft\Windows\SystemData\S-$\ReadOnly\LockScreen\*[*] %ProgramData%\Microsoft\Windows\SystemData\S-$\ReadOnly\PicturePassword\*[*] %ProgramData%\Microsoft\Vault\*[*] %System32%\config\systemprofile\AppData\Local\Microsoft\Vault\*[*] %System32%\config\systemprofile\AppData\Roaming\Microsoft\Vault\*[*] %WINDIR%\Security [edb*.log] %WINDIR%\Security [edb.chk] %WINDIR%\Security\Database [secedit.sdb] HKLM\SYSTEM\MountedDevices [*] HKLM\SYSTEM\CurrentControlSet\Control\Lsa\* [*] HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters [HostName] HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters [NV HostName] HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters [Domain] HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters [NV Domain] HKLM\SYSTEM\CurrentControlSet\Control\ComputerName\ComputerName\* [*] HKLM\SYSTEM\CurrentControlSet\Services\Netlogon [Start] HKLM\SYSTEM\CurrentControlSet\Control\FVEAutoUnlock\* [*] HKLM\SYSTEM\CurrentControlSet\Control\Lsa [FIPSAlgorithmPolicy] HKLM\SYSTEM\CurrentControlSet\Control\Lsa [Security Packages] HKLM\SYSTEM\CurrentControlSet\Control\Lsa\OSConfig\* [*] %WINDIR%\debug [sam.log] HKLM\SECURITY\Policy\PolAcDmS [] %WINDIR%\system32\Microsoft\Protect\*[*] %WINDIR%\system32\Microsoft\Protect\*\User[*] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\* [*] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\setup.exe [*] HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Configuration Manager [RegDebugBreaksEnabled] HKLM\SOFTWARE\Microsoft\Cryptography[MachineGuid] HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider\*[*] HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider Types\*[*] %SYSTEM32%\Microsoft\Crypto\RSA\MachineKeys[*] %SYSTEM32%\Microsoft\Crypto\DSS\MachineKeys[*] %ALLUSERSAPPDATA%\Microsoft\Crypto\RSA\*[*] %ALLUSERSAPPDATA%\Microsoft\Crypto\DSS\*[*] %ALLUSERSAPPDATA%\Microsoft\Crypto\SystemKeys\*[*] %ALLUSERSAPPDATA%\Microsoft\Crypto\Keys[*] %SYSTEMROOT%\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Crypto\Keys[*] %SYSTEMROOT%\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Crypto\Keys[*] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\setup.exe [VerifierDlls] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\setup.exe [GlobalFlag] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\setup.exe [VerifierFlags] HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\setup.exe [PageHeapFlags] HKLM\SOFTWARE\Microsoft\Cryptography[MachineGuid] HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider\*[*] HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider Types\*[*] %SYSTEM32%\Microsoft\Crypto\RSA\MachineKeys[*] %SYSTEM32%\Microsoft\Crypto\DSS\MachineKeys[*] %ALLUSERSAPPDATA%\Microsoft\Crypto\RSA\MachineKeys[*] %ALLUSERSAPPDATA%\Microsoft\Crypto\DSS\MachineKeys[*] %ALLUSERSAPPDATA%\Microsoft\Crypto\Keys[*] %SYSTEMROOT%\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Crypto\Keys[*] %SYSTEMROOT%\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Crypto\Keys[*] %ALLUSERSAPPDATA%\Microsoft\Crypto\RSA\MachineKeys %ALLUSERSAPPDATA%\Microsoft\Crypto\DSS\MachineKeys HKLM\SOFTWARE\Microsoft\Cryptography[MachineGuid] HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider\*[*] HKLM\SOFTWARE\Microsoft\Cryptography\Defaults\Provider Types\*[*] %SYSTEM32%\Microsoft\Crypto\RSA\MachineKeys[*] %SYSTEM32%\Microsoft\Crypto\DSS\MachineKeys[*] %ALLUSERSAPPDATA%\Microsoft\Crypto\Keys[*] %SYSTEMROOT%\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Crypto\Keys[*] %SYSTEMROOT%\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Crypto\Keys[*] %WINDIR%\system32\Microsoft\Protect\Recovery[*] %ALLUSERSAPPDATA%\Microsoft\Crypto\RSA\MachineKeys[*] %ALLUSERSAPPDATA%\Microsoft\Crypto\DSS\MachineKeys[*] HKLM\SECURITY\Policy\PolAcDmS [] HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Audit\* [*] HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Credssp\* [*] HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Data\* [*] HKLM\SYSTEM\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy\* [*] HKLM\SYSTEM\CurrentControlSet\Control\Lsa\GBG\* [*] HKLM\SYSTEM\CurrentControlSet\Control\Lsa\JD\* [*] HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Kerberos\* [*] HKLM\SYSTEM\CurrentControlSet\Control\Lsa\MSV1_0\* [*] HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Skew1\* [*] HKLM\SYSTEM\CurrentControlSet\Control\Lsa\SSO\* [*] HKLM\SYSTEM\CurrentControlSet\Control\Lsa\SspiCache\* [*] %WINDIR%\Security [edb*.log] %WINDIR%\Security [edb.chk] %WINDIR%\Security\Database [secedit.sdb] %WINDIR%\debug [sam.log] %WINDIR%\system32\Microsoft\Protect\*[*] %WINDIR%\system32\Microsoft\Protect\*\User[*]