I’m querying Windows systems for unquoted path strings in a certain registry location.
The query I’m using is
q: values “ImagePath” whose (it as string as lowercase contains “C:” as lowercase) of keys of keys “HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services” of ( x64 registries; x32 registries )
I’d like to return only results that aren’t in quotes. For instance, the results from the above query returns
A: “C:\Program Files (x86)\BigFix Enterprise\BES Client\BESClient.exe”%00
A: C:\Program Files (x86)\Brother\BRAdmin Professional 3\bratimer.exe%00
And I’d like to only return the second line or any line that does not start with a double quote. I imagine it’s a simple thing but I haven’t been able to find an example that I can alter to fit so far.