Registry Hives

..................................................................................................................................................

The following registry keys are extracted and reported on by OnScene LHF. Many of these registry keys are a source of  valuable evidence during computer forensic investigations.

OnScene LHF will allow you to add your own registry keys. This can be useful for software licensing audits.

Registry Location:

HKCU

Key Location:

\Software\Microsoft\CurrentVersion\Applets\Paint\Recent File List

Description:

..................................................................................................................................................

Registry Location:

HKCU

Key Location:

\Software\Microsoft\CurrentVersion\Applets\RegEdit

Description:

The LastKey value maintains the last key accessed using RegEdit

..................................................................................................................................................

Registry Location:

HKCU

Key Location:

\Software\Microsoft\CurrentVersion\Applets\RegEdit\Favorites

Description:

Maintains a list of favorites added through Favorites menu item in RegEdit

..................................................................................................................................................

Registry Location:

HKCU

Key Location:

\Software\Microsoft\CurrentVersion\Applets\WordPad\Recent File List

Description:

List of files accessed/saved in WordPad

..................................................................................................................................................

Registry Location:

HKCU

Key Location:

\Software\Microsoft\Search Assistant\ACMru

Description:

Maintains a list of items searched for via Start->Search; the subkeys (5001, 5603, 5604, etc.) correspond to the textfields where the user enters search parameters.

..................................................................................................................................................

Registry Location:

HKCU

Key Location:

\Software\Microsoft\Internet Explorer\TypedURLs

Description:

Maintains a list of URLs typed into the IE Address bar

..................................................................................................................................................

Registry Location:

HKCU

Key Location:

\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs

Description:

Maintains a list of items recently accessed

..................................................................................................................................................

Registry Location:

HKCU

Key Location:

\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedMRU

Description:

Maintains a list of programs accessed, and their locations within the file system. Sort via the MRUList.

..................................................................................................................................................

Registry Location:

HKCU

Key Location:

\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU

Description:

Maintains a list of files that are opened or saved via Windows Explorer-style dialog boxes

..................................................................................................................................................

Registry Location:

HKCU

Key Location:

\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRU

Description:

Maintains a list of video streams opened by media applications

..................................................................................................................................................

Triage LHF module reports on this key

194 Registry Hives: 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20    [ view all ]

Computer Forensics Experts

Creating an Image with OSI

Previewing PST Files

On Scene Computer Forensics

Copy with MD5 report

Windows Recycle Bin

Computer Forensics For Apple Mac

Viewing the Internet Cache

Registry Hives



Using OnScene Investigator

Using Registry LHF

Down Data Sheet

Uses for OnScene Investigator

Project Roadmap



Find a Reseller

Become a Reseller




Training Certification


 
 
 
Home I Site Map I About Us I Help I Terms & Conditions
Copyright 2007 www.forensicsmatter.com All Rights Reserved.