Registry Hives

..................................................................................................................................................

The following registry keys are extracted and reported on by OnScene LHF. Many of these registry keys are a source of  valuable evidence during computer forensic investigations.

OnScene LHF will allow you to add your own registry keys. This can be useful for software licensing audits.

Registry Location:

HKLM

Key Location:

\Software\Microsoft\Windows\CurrentVersion\explorer\User Shell Folders\Common Startup

Description:

..................................................................................................................................................

Registry Location:

HKCU

Key Location:

\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Startup

Description:

..................................................................................................................................................

Registry Location:

HKLM

Key Location:

\Software\Microsoft\Windows\CurrentVersion\App Paths

Description:

Each subkey contains the path to the specific application; paths and the actual executables should be verified, as legitimate apps may be set in other autostart locations, and the linked-to application subverted or trojaned.

..................................................................................................................................................

Registry Location:

HKLM

Key Location:

\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options

Description:

This Registry location is used to designate a debugger for an application. Testing shows that it's an excellent redirection facility. For example, adding notepad.exe as a key, and then adding a "Debugger" value of cmd.exe will cause the command prompt to be opened whenever Notepad is launched. File binding utilities will allow an attacker to bind a backdoor to a legitimate program, and then redirect that legit program to the Trojaned one.

..................................................................................................................................................

Triage LHF module reports on this key

194 Registry Hives: 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20    [ view all ]

Computer Forensics Experts

Creating an Image with OSI

Previewing PST Files

On Scene Computer Forensics

Copy with MD5 report

Windows Recycle Bin

Computer Forensics For Apple Mac

Viewing the Internet Cache

Registry Hives



Using OnScene Investigator

Using Registry LHF

Down Data Sheet

Uses for OnScene Investigator

Project Roadmap



Find a Reseller

Become a Reseller




Training Certification


 
 
 
Home I Site Map I About Us I Help I Terms & Conditions
Copyright 2007 www.forensicsmatter.com All Rights Reserved.