Avsnitt Course 36 - Windows Forensics and Tools | Episode 6: From System Hives to Forensic Analysis CyberCode Academy Spela Dela
In this lesson, you’ll learn about: Windows Registry structure and forensic analysis1. What is the Windows Registry? A centralized configuration database in WindowsStores system, user, and application settings 🔹 Core Idea Think of it as the brain of Windows configuration 2. Registry StructureThe registry is organized in a strict hierarchy:🔹 Components HivesKeysSubkeysValues 🔹 Analogy Hive → main database fileKey → folderValue → actual data entry 3. Main Root Keys🔹 Key Windows Registry Roots HKEY_LOCAL_MACHINE (HKLM)HKEY_CURRENT_USER (HKCU) 🔹 What they represent HKLM → system-wide settingsHKCU → settings for the logged-in user 4. Physical Storage of Registry Hives Stored on disk in: C:\Windows\System32\config 🔹 Why this matters Investigators can extract registry data directly from diskEven if Windows is not bootable 5. Core HKLM Sub-Hives🔹 SAM (Security Accounts Manager) Stores:User accountsPassword hashes 🔹 SECURITY Hive Stores:Local security policyLSA secretsAuthentication data 🔹 SOFTWARE Hive Stores:Installed applicationsConfiguration settings 🔹 SYSTEM Hive Stores:DriversServicesBoot configuration 👉 Key Insight: These hives are critical for system and user reconstruction 6. Modern Windows Registry Extensions🔹 Newer Hives BCD (Boot Configuration Data)Controls boot processELAM (Early Launch Anti-Malware)Protects early boot stageBrowser-related application data hives 👉 Purpose: Improve security and system initialization 7. Forensic Extraction Tools🔹 Common Tools FTK ImagerUsed to extract registry hives from diskRegistry viewers (offline analysis tools) 🔹 Why FTK Imager matters Bypasses OS restrictionsWorks on live or dead systems 8. Registry Analysis Workflow🔹 Step-by-step process Acquire disk imageExtract registry hivesLoad into analysis toolExamine keys and values 9. What Investigators Look For🔹 Key Evidence Types User activityInstalled softwareSystem boot historyMalware persistence mechanisms Key Takeaways The registry is a central configuration database for WindowsIt is structured into hives, keys, and valuesCritical hives include SAM, SECURITY, SOFTWARE, SYSTEMRegistry files are physically stored on diskTools like FTK Imager enable offline forensic extraction Big PictureRegistry analysis helps you:👉 Move from system configuration → user and attacker behavior reconstructionMental Model Registry = Windows “black box” of system activity You can listen and download our episodes for free on more than 10 different platforms:https://linktr.ee/cybercode_academy Rss Apple Podcaster →