l Overview: Define the purpose of the Registry Identify the permissions provided to protect the registry Identify the key registry values to protect Understand the steps needed to audit the registry Understand the steps needed to properly backup the registry database Module 7
l DescriptionRegistry
l Registry SubTrees HKEY_LOCAL_MACHINE SYSTEM Clone ControlSet001 ControlSet002 CurrentControlSet Select Current Default Failed LastKnownGood Registry
l Hives l HKEY_LOCAL_MACHINE\SAMSam, Sam.log, Sam.sav l HKEY_LOCAL_MACHINE\SecuritySecurity, Security.log, Security.sav l HKEY_LOCAL_MACHINE\SoftwareSoftware, Software.log, Software.sav l HKEY_LOCAL_MACHINE\SystemSystem, System.alt, System.log, l...
l HKEY_LOCAL_MACHINE\… l SubKeys
l Changing Key Permissions l Read l Full Control l Special Access Registry
l Default Settings l Registry Tools
l Registry Security And Protection
l Security Setting
l Key Registry Values
l Auditing l Key Registry Values
l Backing Up and Restoring Keys l Key Registry Values
l
l