windows registry forensics

15
Taha İslam YILMAZ Computer Engineering TOBB ETU ADEO IWS - Computer Forensics WINDOWS REGISTRY

Upload: taha-yilmaz

Post on 25-Jan-2017

84 views

Category:

Engineering


1 download

TRANSCRIPT

Page 1: Windows registry forensics

Taha İslam YILMAZComputer EngineeringTOBB ETUADEO IWS - Computer Forensics

WINDOWS REGISTRY

Page 2: Windows registry forensics

Windows Registry

• Understanding what registry means and what it does

• How windows registry is built up and what files are used

• Few important keys for forensics in registry • Demo

Page 3: Windows registry forensics

Windows Registry

• Central database of Windows• The database contains most of the settings for

Windows , programs,hardware and users.• Such as , profiles for each user , the applications

installed on the computer , what hardware exist on the system and the last shut down time of computer.

Page 4: Windows registry forensics

Windows Registry

• C:\Windows\System32\config

Page 5: Windows registry forensics

Windows Registry

• HKCR - Contains information about the correct program opens when executing a file with Windows Explorer.

• HKCU - Contains the profile about the user that is logged on.

• HKLM - Contains system-wide hardware settings and configuration information.

Page 6: Windows registry forensics

Windows Registry

• HKU - Contains all user profiles that exist on the system.

Also contains information about the type of hardware installed , default settings of softwares and desktop configurations. These informations is used for all users who log on to this computer. • HKCC - Contains information about the hardware

profile used by the computer start up.

Page 7: Windows registry forensics

Windows Registry

Page 8: Windows registry forensics

Windows Registry

Important informations can be recovered for forensic cases:• System Configuration• Devices on the System• User Names• Web Browsing Activity• Recent Files

Page 9: Windows registry forensics

Windows RegistryReports are created with regripper_2.02• System Configuration• Hive : SYSTEM

Page 10: Windows registry forensics

Windows RegistryReports are created with regripper_2.02• Devices on the System• Hive : SYSTEM

Page 11: Windows registry forensics

Windows RegistryReports are created with regripper_2.02• User Names• Hive : SAM

Page 12: Windows registry forensics

Windows RegistryReports are created with regripper_2.02• Web Browsing Activity• Hive : NTUSER.DAT

Page 13: Windows registry forensics

Windows RegistryReports are created with regripper_2.02• Recent Files• Hive : NTUSER.DAT

Page 14: Windows registry forensics

Windows Registry

DEMO : Few important keys for forensics in registry

Page 15: Windows registry forensics

Thank you for listening to me !