Some Pitfalls of Interpreting Forensic Artifacts in Windows Registry

This post is on behalf of one of our students, Ms. Jacky Fox. Given below is the archive that contains her MSc dissertation and the Bash scripts she wrote to extract and correlate Windows registry artifacts. During her research she discovered that recent versions of Microsoft Windows introduced subtle changes to forensic interpretation of Windows registry keys, including UserAssist and the keys related to USB devices. Modern forensic literature and tools do not reflect these changes – hence this post.

WindowsRegistryForensics.zip

 

 


Posted

in

by

Tags:

Comments

3 responses to “Some Pitfalls of Interpreting Forensic Artifacts in Windows Registry”

  1. Habeeb avatar
    Habeeb

    Thank you for sharing your observations and Learning.

  2. Jason Farina avatar
    Jason Farina

    Thanks. a very interesting read and I look forward to playing with the bash scripts 🙂

  3. Daniel Beaulieu

    Daniel Beaulieu

    I cannot thanks enough for that article.Really thank you!

Leave a Reply to Daniel Beaulieu Cancel reply

Your email address will not be published. Required fields are marked *