Registry Hives

..................................................................................................................................................

The following registry keys are extracted and reported on by OnScene LHF. Many of these registry keys are a source of  valuable evidence during computer forensic investigations.

OnScene LHF will allow you to add your own registry keys. This can be useful for software licensing audits.

Registry Location:

SYSTEM

Key Location:

\ControlSet001\Control\TimeZoneInformation

Description:

Handles the systems timezone

..................................................................................................................................................

Registry Location:

SYSTEM

Key Location:

\ControlSet001\Control\Windows

Description:

Holds the last shutdown time in 64 bit little endian

..................................................................................................................................................

Registry Location:

SYSTEM

Key Location:

\MountedDevices

Description:

Contains a list of mounted devices

..................................................................................................................................................

Registry Location:

SYSTEM

Key Location:

\ControlSet001\Enum\USBSTOR

Description:

Contains a list of mounted usb storage devices setupapi.log file.

..................................................................................................................................................

Registry Location:

SYSTEM

Key Location:

SOFTWARE\Microsoft\Windows NT\CurrentVersion

Description:

Contains version & registration information for windows

..................................................................................................................................................

Registry Location:

SYSTEM

Key Location:

System\ControlSetX\Enum\IDE

Description:

Gives information on various IDE drives (CD, hard drives), what the model was and what order it was installed on the system - UINumber: Specifies a number associated with the device that can be displayed in the user interface.

..................................................................................................................................................

Registry Location:

HKLM

Key Location:

\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management

Description:

Controls whether the system clears the cache file at shutdown

..................................................................................................................................................

Registry Location:

HKLM

Key Location:

E\SYSTEM\CurrentControlSet\Control\Session Manager\Environment

Description:

E\SYSTEM\CurrentControlSet\Control\Session Manager\Environment

..................................................................................................................................................

Registry Location:

HKLM

Key Location:

\SYSTEM\CurrentControlSet\Services\Atapi\Parameters

Description:

Controls whether 48 bit LBA is enabled

..................................................................................................................................................

Registry Location:

HKLM

Key Location:

E\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\KeepRasConnections

Description:

Controls whether remote connections are maintained instead of disconnected when a user logs off a workstation

..................................................................................................................................................

Triage LHF module reports on this key

194 Registry Hives: 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20    [ view all ]

Computer Forensics Experts

Creating an Image with OSI

Previewing PST Files

On Scene Computer Forensics

Copy with MD5 report

Windows Recycle Bin

Computer Forensics For Apple Mac

Viewing the Internet Cache

Registry Hives



Using OnScene Investigator

Using Registry LHF

Down Data Sheet

Uses for OnScene Investigator

Project Roadmap



Find a Reseller

Become a Reseller




Training Certification


 
 
 
Home I Site Map I About Us I Help I Terms & Conditions
Copyright 2007 www.forensicsmatter.com All Rights Reserved.