top of page

Mastering Windows Registry Forensics:

Pages Count

17 Pages

Links for the courses


The Windows Registry: The Black Box Flight Recorder of Your PC

The Registry's Dirty Little Secret: Transaction Logs

SAM Hive: The Registry Knows Who You Are

System Configuration

  1. System Configuration: Reading the Machine's Own Biography

  1. System Configuration: Network Artifacts & Filesystem Timestamps

2.1 Windows Registry: A Forensic Goldmine for Installed Applications

2.2 Tracking Microphone and Camera Usage in Windows (Program Execution: CompatibilityAccessManager)

  1. Registries related to System configuration

  1. System Configuration: Persistence & Shutdown

NTUSER.Dat

  1. NTUSER.Dat : What the User Was Looking For

1.1 RecentDocs: Uncovering User Activity Through Recently Opened Files

1.2 Tracking Recently Opened Files in Microsoft Office: A Forensic Guide

1.3 Tracking Trusted Office Documents: A Key to Investigating Macro-Based Malware


Your Instructor

Dean

Dean
bottom of page