New
#1
How to monitor which app in affecting Registry .
So as the title says , I have this weird issue , every time I start / restart the windows the powershell gets a disallow run key in registry .
Firstly I thought it's because of ExecutionPolicy but I set it to unrestricted and it doesn't change when I restart while when I delete the disallow run key from registry it appear with each re/start , so is there any app/method I can use to determine which app is writing registry ? I mean if I create another user it seems to be fine , so It must be an app on this user .
Thanks in advance![]()