The Windows Registry Forensics course shows you how to examine the live registry, the location of the registry files on the forensic image, and how to extract files.
The Windows Registry Forensics course shows you how to examine the live registry, the location of the registry files on the forensic image, and how to extract files.
4.8 (48 ratings)
RI
Apr 19, 2022
Thank you to my learning instructor, I truly appreciate all the lectures. It's awesome!
MA
Sep 10, 2021
A nice course by a nice instructor on a nice platform.
From the lesson
Software Hive File
This module will show examiners how to locate information of forensic value relating to application execution and installation contained within the software hive file. The module will provide an overview of the forensic artifacts found in the software hive file, such as installed programs and applications, operating system type, install date and time, wireless network information, file association, domain logon information, the last logged-on user, programs set to run at startup and tracking USB devices that were attached to the system.