- •The project has been funded by the European Commission. The Education, Audiovisual and
- •Registry Description
- ••what kind of information is actually stored there?
- •Registry Information
- •Registry’s Structure
- •Physically, Windows organizes the registry as hives stored in binary files. In addition,
- •Registry root keys:
- •HKEY_LOCAL_MACHINE
- •HKEY_LOCAL_MACHINE -HKML
- •HKEY_LOCAL_MACHINE -HKML
- •And what about user data?
- •NTUSER.DAT location in Windows XP
- •NTUSER.DAT location in Windows 7
- •Registry Files Examination
- •Getting information about connected USB devices
- •When a removable USB device (for example, a flash drive) is connected to
- •Keys are created in this registry branch, each of which represents its own
- •To get the time of the last USB device connection, you should take
- •System Information
- •Getting information about connecting network cards
- •Network Neighborhood Information
- •Additional information may be found in the following key of the hive
- •Wireless network
- •Detailed information can be obtained by linking these identifiers with signatures from the
- •The summary data contains the following important information:
- •Use DCode-v4.02a-build-4.02.0.9306 to translate the date and time format
- •RESTORE POINTS vs. VOLUME SHADOW COPY
- •RESTORE POINTS vs. VOLUME SHADOW
- •RESTORE POINTS (Windows XP)
- •RESTORE POINTS (Windows 7)
- •RESTORE POINTS (Windows XP)
- •VOLUME SHADOW COPY
- •USER PROFILES
- •Which Version ?
- •Application Data
- •Application Data (subfolders)
- •SUMMARY
RESTORE POINTS vs. VOLUME SHADOW COPY
•History of Restore Points & Volume Shadow Copy
•Benefits for Windows operating system
•Client vs. Server side of Windows operating systems
•Location of Restore Points & Volume Shadow Copy
RESTORE POINTS vs. VOLUME SHADOW
COPY
• History of Restore Points & Volume Shadow Copy
RESTORE POINTS (Windows XP)
RESTORE POINTS (Windows 7)
RESTORE POINTS (Windows XP)
HKLM\SOFTWARE\Microsoft\WindowsNT\CurrentVersion\SystemRestore
VOLUME SHADOW COPY
•Shadow Explorer ver.0.9
•vssadmin
–vssadmin list shadows /for=C:
–mklink /d c:\sc1 \\?\GLOBALROOT\Device\ HarddiskVolumeShadowCopy7\
•PDE – Physical Disk Emulator in EnCase v.7
USER PROFILES
•Contains user configuration settings / files on a Windows XP\Vista\7 system.
|
|
Location Found |
Windows Version |
SystemRoot |
Note: XP systems upgrade |
|
from NT may have profile |
|
located here |
|
|
Documents and Settings\Username |
XP |
|
|
\Users |
Vista, 7, 8 |
|
|
Which Version ?
Windows 7 / 8
Windows
XP
Application Data
• Contains application specific data of the user
|
|
Location |
Windows Version |
Documents and Settings\Username |
XP |
|
|
Documents and Settings\Username\Local |
XP – Non Roaming |
Settings |
|
|
|
Users\User\AppData |
Vista, 7, 8 |
|
|
Application Data (subfolders)
• Local
• LocalLow
• Roaming
