In this lesson, you’ll learn about: Windows Registry artifacts and UserAssist forensics1. Why Registry Artifacts Matter The Windows Registry stores hidden traces of user activityInvestigators use it to reconstruct:User behaviorApplication usageSystem timelines 🔹 Key Idea Every click and execution leaves a forensic footprint 2. Common Digital Footprints in Windows🔹 Types of artifacts Internet browsing historyEmail attachmentsSkype / communication logsRecently used files (MRU lists)Executed programs 👉 Key Insight: Even deleted actions often remain in registry traces 3. The UserAssist Key🔹 What is it? A Windows Registry key that tracks program execution history 🔹 What it records Application nameRun count (how many times launched)Last execution timestampUsage frequency 👉 Why it matters: Shows what a user actually ran, not just what exists on disk 4. ROT13 Obfuscation🔹 What Windows does UserAssist entries are encoded using a simple cipher:ROT13 cipher 🔹 Purpose Obscures readable program namesPrevents casual inspection 👉 Important Insight: It is not encryption, just basic encoding 5. Decoding UserAssist Data🔹 Tools used by investigators UserAssistViewMagnet Forensics tools 🔹 What they do Decode ROT13 valuesConvert registry entries into readable formatDisplay execution history clearly 6. Building a Forensic Timeline🔹 What investigators reconstruct When programs were openedHow often they were usedSequence of user actions 🔹 Why it matters Helps establish:IntentBehavior patternsPossible malicious activity 7. Investigative Value of UserAssist🔹 What it reveals User activity patternsApplication usage frequencyTime-based behavior analysis 👉 Key Insight: It helps answer: “What did the user actually do on the system?” 8. Forensic Importance Supports legal investigationsHelps detect insider threatsBuilds evidence timelines Key Takeaways Windows Registry contains deep user activity artifactsUserAssist tracks executed programs and usage behaviorData is encoded using ROT13, not securely encryptedSpecialized tools are needed to decode and analyze entriesIt is essential for building accurate forensic timelines Big PictureUserAssist helps investigators:👉 Move from static system data → real user behavior reconstructionMental Model Program run → Registry entry → Encoded record → Decoded timeline You can listen and download our episodes for free on more than 10 different platforms:https://linktr.ee/cybercode_academy Rss Apple Podcaster →