PHASE: Registry Hives33% COMPLETION
Abort Mission
MODULE 04

Windows Forensics: Registry

Analyzing the Windows Registry for user activity, USB history, and autoruns.

Registry Hives

The Windows Registry is a hierarchical database storing system and user settings.

HKEY_LOCAL_MACHINE\SYSTEM - System configuration
HKEY_CURRENT_USER\Software - User-installed apps
NTUSER.DAT - User-specific settings