Case Studies
User Hives
Abstract
This chapter discusses a great deal of the data that can be extracted from Registry hives found within a user profile in order to illustrate indicators of patterns of activity. This information can be used by analysts to demonstrate when the user was logged into the system, as well as locate indicators of malware infections, intrusions, and a number of other activities.
Keywords
MuiCache; NTUSER.DAT; RecentDocs; Registry; User; UserAssist; USRCLASS.DAT; WordWheelQueryIntroduction
Get Windows Registry Forensics, 2nd Edition now with the O’Reilly learning platform.
O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.