drop registry export and system evtx csv · detect write blocker configuration in registry · identify attempts to write to a read-only protected device · surface write blocker bypass attempts · runs locally
StorageDevicePolicies\WriteProtect · 4657 policy changes · write-denied system events · registry snapshot diff · integrity score
drop registry export · system evtx csv · optional mft csv