PHASE: Registry Hives33% COMPLETION
MODULE 04
Windows Forensics: Registry
Analyzing the Windows Registry for user activity, USB history, and autoruns.
Registry Hives
The Windows Registry is a hierarchical database storing system and user settings.
HKEY_LOCAL_MACHINE\SYSTEM - System configuration
HKEY_CURRENT_USER\Software - User-installed apps
NTUSER.DAT - User-specific settings