Presentation is loading. Please wait.

Presentation is loading. Please wait.

FORENSICS ANALYSIS OF THE REGISTRY OF WINDOWS 7 “SYSTEM ANALYSIS” 시스템 포렌식 실습 NURHALIMATUSADIAH SYARA 10152146 시스템 포렌식 실습.

Similar presentations


Presentation on theme: "FORENSICS ANALYSIS OF THE REGISTRY OF WINDOWS 7 “SYSTEM ANALYSIS” 시스템 포렌식 실습 NURHALIMATUSADIAH SYARA 10152146 시스템 포렌식 실습."— Presentation transcript:

1 FORENSICS ANALYSIS OF THE REGISTRY OF WINDOWS 7 “SYSTEM ANALYSIS” 시스템 포렌식 실습 NURHALIMATUSADIAH SYARA 10152146 시스템 포렌식 실습

2 Windows Registry the system such as the settings configuration of the system 시스템 포렌식 실습

3 The computer name is available in the following registry sub key: HKEY_LOCAL_MACHINE\SYSTEM\Currentcontrolset\ Control\ComputerName\ComputerName HKEY_LOCAL_MACHINE is hive connected to Keys - SYSTEM is Keys - Currentcontrolset is SubKeys - Control is SubKeys - ComputerNameis SubKeys - ComputerName is value that store data ; 시스템 포렌식 실습

4 HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralPro cessor\0 HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralPro cessor\1 This information includes the processor name, its speed and vendor identifier. We can know name of processor of this computer ; Intel® Core™ i3 – 5005U CPU @ 2.00GHz 시스템 포렌식 실습

5 This key maintains a list of recently opened or saved files via typical Windows Explorer-style commons dialog boxes HKCU\Software\Microsoft\Windows\CurrentsVersion\Explorer\ComDIg3 2\OpenSaveMRU 시스템 포렌식 실습

6 This key maintains a list of entries (E.G full file path or commands like cmd, regedit, compmgmnt.MSC) executed using the start>run commands HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU 시스템 포렌식 실습

7 IMPORTANT REGISTRY ENTRIES HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\ HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU\ HKCU\Software\Microsoft\Internet Explorer\TypedURLs\ HKCU\Software\Microsoft\Windows\CurrentVersion\ComDIg32\OpenSaveMRU HKCU\Software\Microsoft\Windows\CurrentVersion\ComDIg32\LastVisitedMRU 시스템 포렌식 실습

8 If we want t reactivate on new machine HKCU\Software\Microsoft\Windows\CurrentVersion\Setup\OOBE 시스템 포렌식 실습

9 IF WE CHANGE THE NUMBER OF VALUE DATA. SO, WHEN WE CLOSE IT WE CAN’T OPEN IT 시스템 포렌식 실습


Download ppt "FORENSICS ANALYSIS OF THE REGISTRY OF WINDOWS 7 “SYSTEM ANALYSIS” 시스템 포렌식 실습 NURHALIMATUSADIAH SYARA 10152146 시스템 포렌식 실습."

Similar presentations


Ads by Google