Skip to main content
The registry_manager class provides Windows registry emulation by parsing real registry hive files and supporting runtime modifications through an overlay system.

Overview

This class implements registry functionality by:
  • Parsing Windows registry hive files (NTUSER.DAT, SOFTWARE, SYSTEM, etc.)
  • Providing read access to registry keys and values
  • Supporting runtime modifications via an in-memory overlay
  • Path normalization and redirection
  • Serialization for state persistence
  • Type-safe value accessors

Constructors

Default Constructor

Creates a registry manager without loading any hives.

Hive Path Constructor

const std::filesystem::path&
Directory containing Windows registry hive files
Automatically loads standard hives (SYSTEM, SOFTWARE, etc.) from the specified directory.

Destructor

Cleans up all loaded hives and associated resources.

Move Semantics

The class supports move construction and assignment but prohibits copying:

Key Operations

get_key

Retrieves a registry key by path.
const utils::path_key&
Full registry path (e.g., HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft)
Returns: A registry_key object if found, or std::nullopt otherwise. Example:

Value Operations

get_value (by name)

Retrieves a registry value by name.
const registry_key&
The registry key containing the value
std::string_view
Name of the value to retrieve (empty string for default value)
Returns: A registry_value structure if found, or std::nullopt otherwise.

get_value (by index)

Retrieves a registry value by enumeration index.
const registry_key&
The registry key containing the value
size_t
Zero-based index of the value to retrieve
Returns: The value at the specified index, or std::nullopt if index is out of range.

set_value

Writes a value to the registry overlay (runtime modifications only).
const registry_key&
The registry key to write to
std::string
Name of the value to set
uint32_t
Registry value type (REG_SZ, REG_DWORD, etc.)
std::span<const std::byte>
Raw value data
Note: Changes are stored in memory and can be serialized for persistence.

Subkey Operations

get_sub_key_name

Retrieves the name of a subkey by index.
const registry_key&
The parent registry key
size_t
Zero-based index of the subkey
Returns: The subkey name if index is valid, or std::nullopt otherwise.

Advanced Access

get_hive_key

Retrieves direct access to the underlying hive key structure.
const registry_key&
The registry key to expose
Returns: An exposed_hive_key structure containing:
  • key: Reference to the internal hive_key structure
  • file: Reference to the hive file stream
Note: This is a low-level interface for direct hive manipulation.

read_u16string

Reads a UTF-16 string value by index.
const registry_key&
The registry key containing the value
size_t
Index of the string value
Returns: The UTF-16 string if the value exists and is a string type.

Serialization

serialize_runtime_state

utils::buffer_serializer&
Output buffer for serialized state
Serializes runtime modifications (overlay values) to a buffer.

deserialize_runtime_state

utils::buffer_deserializer&
Input buffer containing serialized state
Restores runtime modifications from a serialized buffer.

Data Structures

registry_key

Represents a registry key handle.

registry_value

Represents a registry value with type-safe accessors.
Type checking methods:
  • is_dword(): Returns true if type is REG_DWORD
  • is_string(): Returns true if type is REG_SZ
Type conversion methods:
  • as_dword(): Converts to DWORD if type matches
  • as_string(): Converts to UTF-16 string if type matches

Registry Type Constants

Usage Example

Path Normalization

The registry manager automatically handles:
  • Case-insensitive key and value names
  • Path redirection (e.g., HKLM → HKEY_LOCAL_MACHINE)
  • Forward slash to backslash conversion
  • Leading/trailing slash removal

Standard Hive Mapping

When initialized with a hive directory, the following files are loaded:
  • SYSTEM → HKEY_LOCAL_MACHINE\SYSTEM
  • SOFTWARE → HKEY_LOCAL_MACHINE\SOFTWARE
  • NTUSER.DAT → HKEY_CURRENT_USER
  • SAM → HKEY_LOCAL_MACHINE\SAM
  • SECURITY → HKEY_LOCAL_MACHINE\SECURITY

See Also