ForensicsWiki will continue to operate as it has before and will not be shutting down. Thank you for your continued support of ForensicsWiki.

Difference between pages "Windows Registry" and "File:EF adn.png"

From ForensicsWiki
(Difference between pages)
Jump to: navigation, search
m (Bibliography)
(uploaded a new version of "File:EF adn.png")
Line 1: Line 1:
* Recovering Deleted Data From the Windows Registry. Timothy Morgan, DFRWS 2008 [ [paper]] [ [slides]]
* [
* [ Forensic Analysis of the Windows Registry in Memory], Brendan Dolan-Gavitt, DFRWS 2008  [ [slides]]
* [ Forensic Analysis of the Windows Registry], Peter Davies, Computer Forensics: Coursework 2 (student paper)
* [ A Windows Registry Quick-Reference], Derrick Farmer, Burlington, VT.
* [ The Windows Registry as a forensic resource], Digital Investigation, Volume 2, Issue 3, September 2005, Pages 201--205.
* [ Forensic Analysis of the Windows Registry], Lih Wern Wong , School of Computer and Information Science, Edith Cowan University
===Open Source===
* [ regviewer] -- a tool for looking at the registry.
* [ RegRipper] --- "the fastest, easiest, and best tool for registry analysis in forensics examinations."
* [ Abexo Free Regisry Cleaner]
* [ Auslogics Registry Defrag]
==See Also==
* [ Windows Incident Response Articles on Registry]
* [ Windows Registry Information]
* [ Wikipedia Article on Windows Registry]

Revision as of 14:19, 11 April 2011