Добавил:
AAA1
aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
Опубликованный материал нарушает ваши авторские права? Сообщите нам.
Вуз:
Предмет:
Файл:4-1 Основи цифрової криміналістики / лк / lecture 8. Windows registry.pptx
X
- •The project has been funded by the European Commission. The Education, Audiovisual and
- •Registry Description
- ••what kind of information is actually stored there?
- •Registry Information
- •Registry’s Structure
- •Physically, Windows organizes the registry as hives stored in binary files. In addition,
- •Registry root keys:
- •HKEY_LOCAL_MACHINE
- •HKEY_LOCAL_MACHINE -HKML
- •HKEY_LOCAL_MACHINE -HKML
- •And what about user data?
- •NTUSER.DAT location in Windows XP
- •NTUSER.DAT location in Windows 7
- •Registry Files Examination
- •Getting information about connected USB devices
- •When a removable USB device (for example, a flash drive) is connected to
- •Keys are created in this registry branch, each of which represents its own
- •To get the time of the last USB device connection, you should take
- •System Information
- •Getting information about connecting network cards
- •Network Neighborhood Information
- •Additional information may be found in the following key of the hive
- •Wireless network
- •Detailed information can be obtained by linking these identifiers with signatures from the
- •The summary data contains the following important information:
- •Use DCode-v4.02a-build-4.02.0.9306 to translate the date and time format
- •RESTORE POINTS vs. VOLUME SHADOW COPY
- •RESTORE POINTS vs. VOLUME SHADOW
- •RESTORE POINTS (Windows XP)
- •RESTORE POINTS (Windows 7)
- •RESTORE POINTS (Windows XP)
- •VOLUME SHADOW COPY
- •USER PROFILES
- •Which Version ?
- •Application Data
- •Application Data (subfolders)
- •SUMMARY
Соседние файлы в папке лк
