Return to lecture notes index
February 23, 2012 (Lecture 11)
The Windows Registry
Today we discussed the Windows registry: It's organization, the persistent components on disk and the volatile components in memory, it's structure, and its forensic value

I strongly recommend the following resources:

A Few Forensic Applications

Below are a few example items I have commonly found useful within the Registry. There are certainly plenty more: