Skip to main content

Table Of Contents

  • Windows OS Details
    • Windows 10 & 11 Versions
    • Windows Server Versions
    • Windows “NT” Versions
    • Windows Administrative Binaries
    • Environment Variables
    • Windows Key Files & Locations
    • Registry Run Keys

WINDOWS OS DETAILS

  • Note: This section details important Windows operating system information across many different versions such as: Windows XP, 7, 10, 11, and Windows Server. Details in this section include version number and dates released, administrative binary information, environmental variables, important registry locations and more.

WINDOWS 10 & 11 VERSIONS

  • Note: Windows 10 versions include Home, Pro, Education, Enterprise, Pro for Workstations, Pro Education, Windows 10 S, and Windows 10 Enterprise LTSC
IDVERSIONDATE RELEASED
1511Windows 10 – Threshold 22015-11-12
1607Windows 10 – Redstone 12016-08-02
1703Windows 10 – Redstone 22017-04-05
1709Windows 10 – Redstone 32017-10-17
1803Windows 10 – Redstone 42018-04-30
1809Windows 10 – Redstone 52018-11-13
1903Windows 10 – 19H12019-05-21
1909Windows 10 – Vanadium2019-11-12
2004Windows 10 - Vibranium2020-05-27
20H2Windows 10 - Vibranium2020-10-20
21H1Windows 10 - Vibranium2021-05-18
21H2Windows 10 - Vibranium2021-11-16
21H2Windows 11 - Sun Valley2021-10-05

WINDOWS SERVER VERSIONS

  • Note: Windows servers include Windows Server Essentials, Windows Server Standard, Windows and Server Datacenter.
IDOSDATE RELEASED
1607Windows Server 20162016-10-12
1709Windows Server2017-10-17
1803Windows Server2018-04-10
1809Windows Server2018-11-13
1809Windows Server 20192018-11-13
1903Windows Server2019-11-12
1909Windows Server2019-11-12
2004Windows Server2020-06-26
20H2Windows Server2020-10-20
21H2Windows Server 20222021-08-18

WINDOWS 'NT' VERSIONS

IDVERSION
NT 3.1Windows NT 3.1 (All)
NT 3.5Windows NT 3.5 (All)
NT 3.51Windows NT 3.51 (All)
NT 4.0Windows NT 4.0 (All)
NT 5.0Windows 2000 (All)
NT 5.1Windows XP (Home, Pro, MC, Tablet PC, Starter, Embedded)
NT 5.2Windows XP (64-bit, Pro 64-bit)
NT 5.2Windows Server 2003 & R2 (Standard, Enterprise)
NT 5.2Windows Home Server
NT 6.0Windows Vista (Starter, Home, Basic, Home Premium, Business, Enterprise, Ultimate)
NT 6.0Windows Server 2008 (Foundation, Standard, Enterprise)
NT 6.1Windows 7 (Starter, Home, Pro, Enterprise, Ultimate)
NT 6.1Windows Server 2008 R2 (Foundation, Standard, Enterprise)
NT 6.2Windows 8 (x86/64, Pro, Enterprise, Windows RT (ARM))
NT 6.2Windows Phone 8
NT 6.2Windows Server 2012 (Foundation, Essentials, Standard)
NT 6.3Windows 8.1 (Pro, Enterprise)
NT 10Windows 10 version 1507

WINDOWS ADMINISTRATIVE BINARIES

EXECUTABLENAME
lusrmgr.mscLocal user and group manager
services.mscServices control panel
taskmgr.exeTask manager
secpol.mscLocal security policy editor
eventvwr.mscEvent viewer
regedit.exeRegistry editor
gpedit.mscGroup policy editor
control.exeControl panel
ncpa.cplNetwork connections manager
devmgmt.mscDevice manager editor
diskmgmt.mscDisk manager editor

ENVIRONMENT VARIABLES

ENVIRONMENT VARIABLEDESCRIPTION AND LOCATION
%SYSTEMROOT%Points to Windows folder (Commonly: C:\Windows)
%APPDATA%Points to user roaming directory Commonly (C:\Users<USERNAME>\AppData\Roaming)
%COMPUTERNAME%The computer hostname
%HOMEDRIVE%Points to default OS drive (Commonly: C:\ )
%HOMEPATH%Points to user directory (Commonly: C:\Users<USERNAME> )
%PATH%When a command is run without a full path (for example: ipconfig) the OS searches all file paths contained in the PATH environmental variable for this file
%PATHEXT%When a command is run without an extension (for example: ipconfig) the OS searches for file matches that INCLUDE extensions from this PATHEXT list
%SYSTEMDRIVE%Points to default OS drive (Commonly: C:\ )
%TMP% && %TEMP%Points to user temp folders (Commonly: C:\Users<USERNAME>\AppData\Local\Temp)
%USERPROFILE%Points to user directories (Commonly: C:\Users<USERNAME> )
%WINDIR%Points to Windows directory (Commonly: C:\Windows)
%ALLUSERSPROFILE%Points to Windows directory (Commonly: C:\ProgramData Windows 10+)

WINDOWS KEY FILES AND LOCATIONS

  • Note: All file paths marked “(WinXP)” are Windows XP only. All others are tested and working with Windows 10+.
LOCATIONFILE CATEGORY
%SYSTEMROOT%\System32\drivers\etc\hostsDNS entries
%SYSTEMROOT%\System32\drivers\etc\networksNetwork settings
%SYSTEMROOT%\System32\config\SAMUser & password hashes
%SYSTEMROOT%\repair\SAMBackup copy of SAM (WinXP)
%SYSTEMROOT%\System32\config\RegBack\SAMBackup copy of SAM
%WINDIR%\System32\config\AppEvent.EvtApplication Log (WinXP)
%WINDIR%\System32\config\SecEvent.EvtSecurity Log (WinXP)
%WINDIR%\System32\config\SECURITYSecurity Log
%WINDIR%\System32\config\APPLICATIONApplication Log
%ALLUSERSPROFILE%\Start Menu\Programs\Startup\Startup Location (WinXP)
%USERPROFILE%\Appdata\Roaming\Microsoft\Windows\Start Menu\Programs\StartupStartup Folder
%WINDIR%\Panther\Commonly used unattend install files
%WINDIR%\System32\SysprepCommonly used unattend install files
%WINDIR%\kb*Installed patches (WinXP)

REGISTRY RUN KEYS

  • Note: Some of these keys are also reflected under HKLM\Software\WOW6432Node on systems running a 64-bit version of Windows.
  • Note: Windows Sysinternals Autoruns is an excellent utility to inspect and monitor auto-starting locations on Windows.
List of registry keys accessed during system boot (in load order):
(WinXP) HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\BootExecute
HKLM\System\CurrentControlSet\Services \ Start value of 0 = Kernel Drivers (Load before Kernel initiation) \ Start value of 2 = Auto-Start \ Start value of 3 = Manual-Start
(WinXP) HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
(WinXP) HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices
(WinXP) HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon /v Userinit
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon /v Shell
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon /v Shell
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
(WinXP) HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
(WinXP) HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
(WinXP) HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows\load
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler (XP, NT, W2k only)