Windows Registry

From Forensics Wiki
Revision as of 14:09, 18 November 2008 by .FUF (Talk | contribs)

Jump to: navigation, search

Contents

Bibliography

  • Recovering Deleted Data From the Windows Registry. Timothy Morgan, DFRWS 2008 [paper] [slides]
  • [1]

Tools

Open Source

  • [2] — "small command line utility for reading and querying Windows NT-based registries."
  • regviewer — a tool for looking at the registry.
  • RegRipper — "the fastest, easiest, and best tool for registry analysis in forensics examinations."

Commercial

See Also