Return to lecture notes index
October 3, 2013 (Lecture 12)
The Windows Registry
Today we discussed the Windows registry: It's organization, the persistent components on disk and the volatile components in memory, it's structure, and its forensic value

I strongly recommend the following resources:

A Few Forensic Applications

Below are a few example items I have commonly found useful within the Registry. There are certainly plenty more: