Difference between pages "Windows Registry" and "Upcoming events"

From ForensicsWiki
(Difference between pages)
Jump to: navigation, search
(Added file locations)
 
(Calls For Papers)
 
Line 1: Line 1:
==Bibliography==
+
<b>PLEASE READ BEFORE YOU EDIT THE LISTS BELOW</b><br>
* Recovering Deleted Data From the Windows Registry. Timothy Morgan, DFRWS 2008 [http://www.dfrws.org/2008/proceedings/p33-morgan.pdf [paper]] [http://www.dfrws.org/2008/proceedings/p33-morgan_pres.pdf [slides]]
+
When events begin the same day, events of a longer length should be listed first. New postings of events with the same date(s) as other events should be added after events already in the list. Please use three-letter month abbreviations (i.e. Sep, NOT Sept. or September), use two digit dates (i.e. Jan 01 NOT Jan 1), and use date ranges rather than listing every date during an event(i.e. Jan 02-05, NOT Jan 02, 03, 04, 05).<br>
* [http://www.pkdavies.co.uk/documents/Computer_Forensics/registry_examination.pdf]
+
<i>Some events may be <u>limited</u> to <b>Law Enforcement Only</b> or to a specific audience. Such restrictions should be noted when known.</i>
  
* [http://dfrws.org/2008/proceedings/p26-dolan-gavitt.pdf Forensic Analysis of the Windows Registry in Memory], Brendan Dolan-Gavitt, DFRWS 2008  [http://dfrws.org/2008/proceedings/p26-dolan-gavitt_pres.pdf [slides]]
+
This is a BY DATE listing of upcoming events relevant to [[digital forensics]]. It is not an all inclusive list, but includes most well-known activities. Some events may duplicate events on the generic [[conferences]] page, but entries in this list have specific dates and locations for the upcoming event.
* [http://www.pkdavies.co.uk/documents/Computer_Forensics/registry_examination.pdf Forensic Analysis of the Windows Registry], Peter Davies, Computer Forensics: Coursework 2 (student paper)
+
* [http://eptuners.com/forensics/A%20Windows%20Registry%20Quick%20Reference.pdf A Windows Registry Quick-Reference], Derrick Farmer, Burlington, VT.
+
  
* [http://www.sciencedirect.com/science?_ob=ArticleURL&_udi=B7CW4-4GX1J3B-1&_user=3326500&_rdoc=1&_fmt=&_orig=search&_sort=d&view=c&_acct=C000060280&_version=1&_urlVersion=0&_userid=3326500&md5=ab887593e7be6d5257696707886978f1 The Windows Registry as a forensic resource], Digital Investigation, Volume 2, Issue 3, September 2005, Pages 201--205.
+
This listing is divided into three sections (described as follows):<br>
 +
<ol><li><b><u>[[Upcoming_events#Calls_For_Papers|Calls For Papers]]</u></b> - Calls for papers for either Journals or for Conferences, relevant to Digital Forensics (Name, Closing Date, URL)</li><br>
 +
<li><b><u>[[Upcoming_events#Conferences|Conferences]]</u></b> - Conferences relevant for Digital Forensics (Name, Date, Location, URL)</li><br>
 +
<li><b><u>[[Training Courses and Providers]]</u></b> - Training </li><br></ol>
  
* [http://www.forensicfocus.com/downloads/forensic-analysis-windows-registry.pdf Forensic Analysis of the Windows Registry], Lih Wern Wong , School of Computer and Information Science, Edith Cowan University
+
== Calls For Papers ==
 +
Please help us keep this up-to-date with deadlines for upcoming conferences that would be appropriate for forensic research.
  
* [http://www.sentinelchicken.com/research/registry_format/ The Windows NT Registry File Format], Timothy D. Morgan
+
{| border="0" cellpadding="2" cellspacing="2" align="top"
 +
|- style="background:#bfbfbf; font-weight: bold"
 +
! width="30%|Title
 +
! width="15%"|Due Date
 +
! width="15%"|Notification Date
 +
! width="40%"|Website
 +
|-
 +
|The Sixth International Workshop on Digital Forensics (WSDF 2013)
 +
|Apr 02, 2013
 +
|May 02, 2013
 +
|http://www.ares-conference.eu/conf/index.php?option=com_content&view=article&id=49&Itemid=95
 +
|-
 +
|New Security Paradigms Workshop (NSPW)
 +
|Apr 12, 2013
 +
|Jun 07, 2013
 +
|http://www.nspw.org/2013/cfp
 +
|-
 +
|5th International Conference on Digital Forensics & Cyber Crime (ICDF2C 2013)
 +
|Apr 30, 2013
 +
|Jun 01, 2013
 +
|http://d-forensics.org/2013/show/cf-papers
 +
|-
 +
|2nd Cyberpatterns: Unifying Design Patterns with Security, Attack and Forensic Patterns Workshop
 +
|May 20, 2013
 +
|Jun 10, 2013
 +
|http://tech.brookes.ac.uk/CyberPatterns2013
 +
|-
 +
|}
  
==File Locations==
+
See also [http://www.wikicfp.com/cfp/servlet/tool.search?q=forensics WikiCFP 'Forensics']
===Windows XP===
+
* HKEY_USERS: \Documents and Setting\User Profile\NTUSER.DAT
+
* HKEY_USERS/DEFAULT: \Windows\system32\config\default
+
* HKEY_LOCAL_MACHIN/SAM: \Windows\system32\config\SAM
+
* HKEY_LOCAL_MACHINE/SECURITY: \Windows\system32\config\SECURITY
+
* HKEY_LOCAL_MACHINE/SOFTWARE: \Windows\system32\config\software
+
* HKEY_LOCAL_MACHINE/SYSTEM: \Windows\system32\config\system
+
  
===Windows 98/ME===
+
== Conferences ==
* \Windows\user.dat
+
{| border="0" cellpadding="2" cellspacing="2" align="top"
* \Windows\system.dat
+
|- style="background:#bfbfbf; font-weight: bold"
* \Windows\profiles\user profile\user.dat
+
! width="40%"|Title
 
+
! width="20%"|Date/Location
==Tools==
+
! width="40%"|Website
===Open Source===
+
|-
* [http://projects.sentinelchicken.org/reglookup/ reglookup] — "small command line utility for reading and querying Windows NT-based registries."
+
|CERIAS 14th Annual Information Security Symposium
* [http://sourceforge.net/projects/regviewer/ regviewer] — a tool for looking at the registry.
+
|Apr 03-04<br>West Lafayette, IN
* [http://www.regripper.net/ RegRipper] — "the fastest, easiest, and best tool for registry analysis in forensics examinations."
+
|http://www.cerias.purdue.edu/site/symposium2013
===Commercial===
+
|-
* [http://www.abexo.com/free-registry-cleaner.htm Abexo Free Regisry Cleaner]
+
|8th Annual Workshop on Digital Forensics and Incident Analysis (WDFIA)
* [http://www.auslogics.com/registry-defrag Auslogics Registry Defrag]
+
|May 08-10<br>Lisbon, Portugal
* [http://lastbit.com/arv/ Alien Registry Viewer]
+
|http://www.wdfia.org/default.asp
* [http://www.larshederer.homepage.t-online.de/erunt/index.htm NT Registry Optimizer]
+
|-
* [http://www.registry-clean.net/free-registry-defrag.htm iExpert Software-Free Registry Defrag]
+
|European Information Security Multi-Conference (EISMC 2013)
* [http://paullee.ru/regundel Registry Undelete (russian)]
+
|May 08-10<br>Lisbon, Portugal
* [http://mitec.cz/wrr.html Windows Registry Recovery]
+
|http://www.eismc.org/
* [http://registrytool.com/ Registry Tool]
+
|-
 +
|IEEE Symposium on Security & Privacy
 +
|May 19-23<br>San Francisco, CA
 +
|http://www.ieee-security.org/TC/SP2013/index.html
 +
|-
 +
|International Workshop on Cyber Crime
 +
|May 24<br>San Francisco, CA
 +
|http://stegano.net/IWCC2013/
 +
|-
 +
|Techno Security and Forensics Investigation Conference
 +
|Jun 02-05<br>Myrtle Beach, SC
 +
|http://www.thetrainingco.com/html/Security%20Conference%202013.html
 +
|-
 +
|Mobile Forensics World
 +
|Jun 02-05<br>Myrtle Beach, SC
 +
|http://www.techsec.com/html/MFC-2013-Spring.html
 +
|-
 +
|ADFSL 2013 Conference on Digital Forensics, Security and Law
 +
|Jun 10-12<br>Richmond, VA
 +
|http://www.digitalforensics-conference.org/index.htm
 +
|-
 +
|FIRST Conference
 +
|Jun 16-21<br>Bangkok, Thailand
 +
|http://conference.first.org/2013/
 +
|-
 +
|The 1st ACM Workshop on Information Hiding and Multimedia Security
 +
|Jun 17-19<br>Montpellier, France
 +
|http://ihmmsec.org/
 +
|-
 +
|28th IFIP TC-11 SEC 2013 International Information Security and Privacy Conference
 +
|Jul 08-10<br>Auckland, New Zealand
 +
|http://www.sec2013.org/
 +
|-
 +
|Symposium On Usable Privacy and Security
 +
|Jul 24-26<br>Newcastle, United Kingdom
 +
|http://cups.cs.cmu.edu/soups/2013/
 +
|-
 +
|DFRWS 2013
 +
|Aug 04-07<br>Monterey, CA
 +
|http://dfrws.org/2013
 +
|-
 +
|Regional Computer Forensics Group GMU 2013
 +
|Aug 05-09<br>Fairfax, VA
 +
|http://www.rcfg.org
 +
|-
 +
|6th USENIX Workshop on Large-Scale Exploits and Emergent Threats (LEET '13)
 +
|Aug 12<br>Washington, DC
 +
|https://www.usenix.org/conferences?page=1
 +
|-
 +
|8th USENIX Workshop on Hot Topics in Security (HotSec '13)
 +
|Aug 13<br>Washington, DC
 +
|https://www.usenix.org/conferences?page=1
 +
|-
 +
|22nd USENIX Security Symposium - USENIX Security '13
 +
|Aug 14-16<br>Washington, DC
 +
|https://www.usenix.org/conference/usenixsecurity13
 +
|-
 +
|6th International Workshop on Digital Forensics (WSDF 2013)
 +
|Sep 02-06<br>Regensburg, Germany
 +
|http://www.ares-conference.eu/conf/index.php?option=com_content&view=article&id=49&Itemid=95
 +
|-
 +
|New Security Paradigms Workshop (NSPW)
 +
|Sep 09-12<br>The Banff Center, Canada
 +
|http://www.nspw.org/current/
 +
|-
 +
|5th International Conference on Digital Forensics & Cyber Crime
 +
|Sep 25-27<br>Moscow, Russia
 +
|http://d-forensics.org/2013/show/home
 +
|-
 +
|VB2013 - the 23rd Virus Bulletin International Conference
 +
|Oct 02-04<br>Berlin, Germany
 +
|http://www.virusbtn.com/conference/vb2013/index
 +
|-
 +
|}
  
 
==See Also==
 
==See Also==
* [http://windowsir.blogspot.com/search/label/Registry Windows Incident Response Articles on Registry]
+
* [[Training Courses and Providers]]
* [http://www.answers.com/topic/win-registry Windows Registry Information]
+
==References==
* [http://en.wikipedia.org/wiki/Windows_Registry Wikipedia Article on Windows Registry]
+
* [http://faculty.cs.tamu.edu/guofei/sec_conf_stat.htm Computer Security Conference Ranking and Statistic]
[[Category:Bibliographies]]
+
* [http://www.kdnuggets.com/meetings/ Meetings and Conferences in Data Mining and Discovery]
* [http://moyix.blogspot.com/search/label/registry Push the Red Button] — Articles on Registry
+
* http://www.conferencealerts.com/data.htm Data Mining Conferences World-Wide]

Revision as of 07:27, 8 April 2013

PLEASE READ BEFORE YOU EDIT THE LISTS BELOW
When events begin the same day, events of a longer length should be listed first. New postings of events with the same date(s) as other events should be added after events already in the list. Please use three-letter month abbreviations (i.e. Sep, NOT Sept. or September), use two digit dates (i.e. Jan 01 NOT Jan 1), and use date ranges rather than listing every date during an event(i.e. Jan 02-05, NOT Jan 02, 03, 04, 05).
Some events may be limited to Law Enforcement Only or to a specific audience. Such restrictions should be noted when known.

This is a BY DATE listing of upcoming events relevant to digital forensics. It is not an all inclusive list, but includes most well-known activities. Some events may duplicate events on the generic conferences page, but entries in this list have specific dates and locations for the upcoming event.

This listing is divided into three sections (described as follows):

  1. Calls For Papers - Calls for papers for either Journals or for Conferences, relevant to Digital Forensics (Name, Closing Date, URL)

  2. Conferences - Conferences relevant for Digital Forensics (Name, Date, Location, URL)

  3. Training Courses and Providers - Training

Calls For Papers

Please help us keep this up-to-date with deadlines for upcoming conferences that would be appropriate for forensic research.

Title Due Date Notification Date Website
The Sixth International Workshop on Digital Forensics (WSDF 2013) Apr 02, 2013 May 02, 2013 http://www.ares-conference.eu/conf/index.php?option=com_content&view=article&id=49&Itemid=95
New Security Paradigms Workshop (NSPW) Apr 12, 2013 Jun 07, 2013 http://www.nspw.org/2013/cfp
5th International Conference on Digital Forensics & Cyber Crime (ICDF2C 2013) Apr 30, 2013 Jun 01, 2013 http://d-forensics.org/2013/show/cf-papers
2nd Cyberpatterns: Unifying Design Patterns with Security, Attack and Forensic Patterns Workshop May 20, 2013 Jun 10, 2013 http://tech.brookes.ac.uk/CyberPatterns2013

See also WikiCFP 'Forensics'

Conferences

Title Date/Location Website
CERIAS 14th Annual Information Security Symposium Apr 03-04
West Lafayette, IN
http://www.cerias.purdue.edu/site/symposium2013
8th Annual Workshop on Digital Forensics and Incident Analysis (WDFIA) May 08-10
Lisbon, Portugal
http://www.wdfia.org/default.asp
European Information Security Multi-Conference (EISMC 2013) May 08-10
Lisbon, Portugal
http://www.eismc.org/
IEEE Symposium on Security & Privacy May 19-23
San Francisco, CA
http://www.ieee-security.org/TC/SP2013/index.html
International Workshop on Cyber Crime May 24
San Francisco, CA
http://stegano.net/IWCC2013/
Techno Security and Forensics Investigation Conference Jun 02-05
Myrtle Beach, SC
http://www.thetrainingco.com/html/Security%20Conference%202013.html
Mobile Forensics World Jun 02-05
Myrtle Beach, SC
http://www.techsec.com/html/MFC-2013-Spring.html
ADFSL 2013 Conference on Digital Forensics, Security and Law Jun 10-12
Richmond, VA
http://www.digitalforensics-conference.org/index.htm
FIRST Conference Jun 16-21
Bangkok, Thailand
http://conference.first.org/2013/
The 1st ACM Workshop on Information Hiding and Multimedia Security Jun 17-19
Montpellier, France
http://ihmmsec.org/
28th IFIP TC-11 SEC 2013 International Information Security and Privacy Conference Jul 08-10
Auckland, New Zealand
http://www.sec2013.org/
Symposium On Usable Privacy and Security Jul 24-26
Newcastle, United Kingdom
http://cups.cs.cmu.edu/soups/2013/
DFRWS 2013 Aug 04-07
Monterey, CA
http://dfrws.org/2013
Regional Computer Forensics Group GMU 2013 Aug 05-09
Fairfax, VA
http://www.rcfg.org
6th USENIX Workshop on Large-Scale Exploits and Emergent Threats (LEET '13) Aug 12
Washington, DC
https://www.usenix.org/conferences?page=1
8th USENIX Workshop on Hot Topics in Security (HotSec '13) Aug 13
Washington, DC
https://www.usenix.org/conferences?page=1
22nd USENIX Security Symposium - USENIX Security '13 Aug 14-16
Washington, DC
https://www.usenix.org/conference/usenixsecurity13
6th International Workshop on Digital Forensics (WSDF 2013) Sep 02-06
Regensburg, Germany
http://www.ares-conference.eu/conf/index.php?option=com_content&view=article&id=49&Itemid=95
New Security Paradigms Workshop (NSPW) Sep 09-12
The Banff Center, Canada
http://www.nspw.org/current/
5th International Conference on Digital Forensics & Cyber Crime Sep 25-27
Moscow, Russia
http://d-forensics.org/2013/show/home
VB2013 - the 23rd Virus Bulletin International Conference Oct 02-04
Berlin, Germany
http://www.virusbtn.com/conference/vb2013/index

See Also

References