WIn10 14393 changed the path structure of the registry. The current method of walking the ParentKCB members ends up duplicating the hive name (i.e., "SYSTEM", "SOFTWARE", etc. show up twice). One of the entries has a KEY_HIVE_ENTRY flag set, and this one is skipped.
WIn10 14393 changed the path structure of the registry. The current method of walking the ParentKCB members ends up duplicating the hive name (i.e., "SYSTEM", "SOFTWARE", etc. show up twice). One of the entries has a KEY_HIVE_ENTRY flag set, and this one is skipped.
This mirrors the change at https://github.com/volatilityfoundation/volatility/commit/c374159750cfbef445889cfbfae61dbb93cdba3f