FORENSICS ANALYSIS OF THE REGISTRY OF WINDOWS 7 “SYSTEM ANALYSIS” 시스템 포렌식 실습 NURHALIMATUSADIAH SYARA 시스템 포렌식 실습
Windows Registry the system such as the settings configuration of the system 시스템 포렌식 실습
The computer name is available in the following registry sub key: HKEY_LOCAL_MACHINE\SYSTEM\Currentcontrolset\ Control\ComputerName\ComputerName HKEY_LOCAL_MACHINE is hive connected to Keys - SYSTEM is Keys - Currentcontrolset is SubKeys - Control is SubKeys - ComputerNameis SubKeys - ComputerName is value that store data ; 시스템 포렌식 실습
HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralPro cessor\0 HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralPro cessor\1 This information includes the processor name, its speed and vendor identifier. We can know name of processor of this computer ; Intel® Core™ i3 – 5005U 2.00GHz 시스템 포렌식 실습
This key maintains a list of recently opened or saved files via typical Windows Explorer-style commons dialog boxes HKCU\Software\Microsoft\Windows\CurrentsVersion\Explorer\ComDIg3 2\OpenSaveMRU 시스템 포렌식 실습
This key maintains a list of entries (E.G full file path or commands like cmd, regedit, compmgmnt.MSC) executed using the start>run commands HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU 시스템 포렌식 실습
IMPORTANT REGISTRY ENTRIES HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\ HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU\ HKCU\Software\Microsoft\Internet Explorer\TypedURLs\ HKCU\Software\Microsoft\Windows\CurrentVersion\ComDIg32\OpenSaveMRU HKCU\Software\Microsoft\Windows\CurrentVersion\ComDIg32\LastVisitedMRU 시스템 포렌식 실습
If we want t reactivate on new machine HKCU\Software\Microsoft\Windows\CurrentVersion\Setup\OOBE 시스템 포렌식 실습
IF WE CHANGE THE NUMBER OF VALUE DATA. SO, WHEN WE CLOSE IT WE CAN’T OPEN IT 시스템 포렌식 실습