Overview
Syllabus
Intro
The Windows Registry
Registry Terminology
Primary Hives Comprising the Registry
Progression of the Registry
Extracting from Offline Hives
Extracting from Live System
Interesting Data Stored in the Registry
What programs have been executed?
Executed Programs: UserAssist
Parsing User Assist
Executed Programs: MuiCache
Executed Programs: AppCompatCache
What Files Have Been Accessed?
Accessed Files: RecentDocs
Accessed Files: ComDlg32
Accessed Files: Office 2013
Shellbags
Anti-Forensics/Cleaning Tools
Privazer Shellbag Cleaner
Effects of CCleaner/Privazer
Anti-Anti Forensics
Timestomping Registry Keys
Combating timestomped registry keys
Questions