Главная
Study mode:
on
1
TryHackMe WindowsForensics
2
Open TryHackMe Windows Forensics room
3
Introduction to Windows Forensics
4
Windows Registry and Forensics
5
Exploring Windows Registry
6
System Information and System Accounts
7
Usage or knowledge of files/folders
8
Evidence of Execution
9
External Devices/USB device forensics
10
Hands-on Challenge
11
Conclusion
Description:
Dive into a comprehensive walkthrough of TryHackMe's Windows Forensics room, focusing on Windows Registry artifacts in digital investigations. Explore Windows Registry Hive locations, software tools for investigation, and the significance of various Windows Registry artifacts. Learn to analyze UserAssist, MRUs, ShellBags, external devices, and more. Follow along with the step-by-step guide covering introduction to Windows forensics, Windows Registry and its role in forensics, exploring the Registry, system information and accounts, file and folder usage evidence, execution traces, and USB device forensics. Conclude with a hands-on challenge to apply your newly acquired knowledge. Gain valuable insights into digital forensic techniques and enhance your skills in Windows-based investigations.

Intro to Windows Forensics - Windows Registry Artifacts

DFIRScience
Add to list
0:00 / 0:00