Windows Registry Forensics Course
1 hour, 6 minutes
Course description
It includes how to examine the live registry, the location of the registry files on the forensic image, and how to extract files. After examining the files with forensic tools, the student can locate relevant artifacts such as USB device connection times, recently used documents, program last run times, and programs set to run at startup.Syllabus
Common Forensic Artifacts found in the registry
Video - 00:51:00
This video shows the location and interpretation of important forensic artifacts in the Windows registry.
The location of Registry files within an image file
Video - 00:03:00
This video shows the location of the registry within the NTFS file system.
The live Registry
Video - 00:09:00
This video shows the structure and function of the live Windows registry.
Registry overview and History
Video - 00:03:00
This video teaches an overview and the history of the Windows registry.
Unlock 7 days of free training
- 1,400+ hands-on courses and labs
- Certification practice exams
- Skill assessments
Plans & pricing
Infosec Skills Personal
$299 / year
- 190+ role-guided learning paths (e.g., Ethical Hacking, Threat Hunting)
- 100s of hands-on labs in cloud-hosted cyber ranges
- Custom certification practice exams (e.g., CISSP, Security+)
- Skill assessments
- Infosec peer community support
Infosec Skills Teams
$799 per license / year
- Team administration and reporting
- Dedicated client success manager
-
Single sign-on (SSO)
Easily authenticate and manage your learners by connecting to any identity provider that supports the SAML 2.0 standard.
-
Integrations via API
Retrieve training performance and engagement metrics and integrate learner data into your existing LMS or HRS.
- 190+ role-guided learning paths and assessments (e.g., Incident Response)
- 100s of hands-on labs in cloud-hosted cyber ranges
- Create and assign custom learning paths
- Custom certification practice exams (e.g., CISSP, CISA)
- Optional upgrade: Guarantee team certification with live boot camps