Hackviser Training
Windows Registry Forensic Analysis
7 sections4 tools
Training Overview
The "Windows Registry Forensic Analysis" training comprehensively teaches how to analyze the Windows Registry in forensic investigations and extract digital evidence. The training covers the fundamental structure and function of the Registry, introducing the tools and techniques used in the collection and analysis of digital evidence.
What you will learn
- The structure of the Windows Registry and the role of hives.
- How to use tools like Registry Explorer and RegRipper for analysis.
- How to find evidence of program execution, user activity, and persistence mechanisms.
- How to analyze artifacts like UserAssist keys.
Tools you will use
- KAPE
- FTK Imager
- Registry Explorer
- RegRipper
Prerequisites
- A solid understanding of the Windows operating system.
- Prior experience with forensic principles is recommended.
Who this is for
- Digital Forensic Investigators.
- Incident Responders.
- Malware Analysts.
Training sections
- 1Introduction
- 2KAPE
- 3FTK
- 4Registry Explorer
- 5UserAssist
- 6RegRipper
- 7Exam
Continue learning
Practice the topic in a lab or continue with a related Hackviser guide.