The Windows Registry

Please read pp. 157-252 of WFA.

Also, look at the article Inside the Registry by Russinovich.

From WFA, page 158:

"To most administrators and forensic analysts, the Registry probably looks the entrance to a dark, forbidding cave on the landscape of the Windows operating system. Others might see the Registry as a dark door at the end of a long hallway, with the words "abandon hope, all ye who enter here" scrawled on it. The truth is that the Registry is a veritable gold mind of information for both the administrator and the forensics investigator.

Why? Well, one reason is that Windows is simply not tidy with respect to the Registry. Some information found in the Registry is old and even inconsistent, but that might sometimes provide us useful historical information.



slide 1/22
* help? contents? restart?Florida State University, 2011