- Log into the EDR console
- Navigate to the 'Process Search' page
- Use the search term regmod: followed by the registry key path to search for as documented below.
regmod:registry\machine\software\classes\*
regmod:registry\user\<SID OF USER>\*
regmod:registry\machine\*
regmod:registry\user\*
regmod:registry\machine\system\*