http://www.forensicmag.com/articles/2015/07/windows-10-registry-forensics-overview
?


Windows 10 Registry Forensics: An Overview

Wed, 07/22/2015 - 2:28am

John J. Barbara

Digital Forensics Consulting, LLC
<http://www.forensicmag.com/company-profiles/digital-forensics-consulting-llc>

Get today's news and top headlines for forensics professionals - Sign up
now! <http://subscriptions.forensicmag.com/?cmpid=textadincontent>

Over the last decade or so, computers have virtually taken over control of
every facet of modern civilization. Every person who uses a computer at
their workplace takes for granted that computers are essential in the work
environment. They store or can access all the information necessary for
normal day-to-day business operations. But there is a dark side to computer
use, or rather computer misuse. Regardless of how many written rules,
policies, and procedures management puts into place to protect the
confidentiality and integrity of their digital information and intellectual
property, it seems inevitable that a breach will eventually occur.

Often the breach happens when an employee intentionally disregards policy
and attaches a USB device to their workplace computer. Although their
intent may be just to upload some pictures to display as a desktop slide
show, they could also download proprietary information. Likewise, they
could unintentionally or intentionally infect the computer with one or more
of the thousands of computer viruses that currently exist.

*The Problem in Perspective*
Consider the following: Presume that an employee attaches a USB device to
his workplace computer at the end of the day intending to download the
company’s customer database which contains thousands of names, addresses,
phone numbers, credit card numbers and so forth. After the download
completes, he removes the USB device and turns off the computer.
Unknowingly to him, a co-worker observed him attaching and removing the USB
device. Since the workday was over, the co-worker could not inform IT
Security until the next day. When IT Security confronts the alleged
perpetrator, he denies the allegation.

How is management and IT Security going to handle this situation to either
prove or disprove the allegation? Probably the best approach would be to
perform an examination of the computer hard drive to look for probative
information. Normally this involves forensically imaging the hard drive in
a controlled environment with one of the many forensic imaging tools. Most
forensic tools incorporate automated built-in features, such as, recovering
deleted folders, performing keyword searches, carving data from unallocated
space, searching directories and files and so forth. The image could then
be examined further, focusing upon the Registry, searching for any USB
devices that may have been attached to the computer.

Often, however, business IT department members lack the necessary
qualifications or experience to perform these types of forensic
examinations. This is not uncommon since IT personnel normally are not
trained as forensic examiners. Under these circumstances, management may
have to contract with an external digital forensics consulting firm to
provide the services. In today’s digital forensics environment, examiners
must have specialized training, knowledge, skills, abilities, tools and
experience to ensure reliable and repeatable results when triaging a live
system or examining a computer hard drive* post-mortem*.

Regardless, it is essential in today’s business environment that management
has a well-documented action plan in place such that if a breach occurs, or
employee misconduct is alleged, they will have a firm foundation to support
and assist with any potential civil or criminal proceedings. Failure to do
so can have a detrimental effect upon the business or corporation.

*What is the Windows Registry?*
A typical Windows OS has many forensically important areas where probative
information can be found, such as in RAM (live system) or stored somewhere
on the computer’s hard drive. Any examination and extraction of probative
information from a live system involves the use of triage tools which
themselves will make changes to those same forensically important areas.
Although this violates the “golden rule” of digital forensics, in some
circumstances there is no alternative. However, before doing so, an
examiner must have previously verified the functionality of the triage
tools and know what changes are made to a live system when those tools are
used.

The Registry, which is a goldmine of potential probative information,
evolved over the years from the early Windows operating systems ‘WIN.INI’
and ‘SYSTEM.INI’ files. When Windows 3.1 was introduced, it was initially
targeted to the corporate work environment and used individual ‘.ini’ human
readable text files which were linked to the ‘WIN.INI’ file. With the
release of Windows 95, the Registry as we know it today was introduced.

[image: Description: Figure 1]Figure 1The Microsoft Computer Dictionary,
Fifth Edition, defines the Registry as: “A central hierarchical database
used in Microsoft Windows 9x, Windows CE, Windows NT, and Windows 2000 used
to store information that is necessary to configure the system for one or
more user’s applications and hardware devices.” Windows XP, Windows Vista,
Windows 7, and Windows 8 all included a Registry. The soon to be released
Windows 10 also contains a Registry and will be the focus of this and
several future columns. (Data relating to the Windows 10 Registry was
obtained from Windows Evaluation Build 9841). Some examples of the
information contained within the Registry which Windows 10 must continually
reference to function includes:

·         USB storage devices that have been attached to the computer.

·         Wireless networks that the computer has connected to.

·         Recent search terms.

·         Lists of the most recently used files or applications.

·         Autorun locations which list applications to run when the
computer is booted.

·         Contents of the User(s) desktop.

·         Malware (if it has installed itself as a service).

*[image: Description: Figure 2]**Figure 2Where is the Information Stored?*
The Windows 10 Registry is not in actuality a central hierarchical database
or one large fi le, but rather a set of files referred to as ‘Hives.’ These
files, located in the “C:\Windows\System32\config” and
“C:\Users\[Username]\” directories, are updated each time a User logs onto
the computer and are shown in Figures 1 and 2. Their contents are as
follows:

·         *C:\Windows\System32\config\DEFAULT*: contains the default system
information which is stored in the “HKEY_USERS\.DEFAULT” Key.

·         *C:\Windows\System32\config\SAM*: contains information about the
Security Accounts Manager (SAM) service which is stored in the “HKLM\SAM”
Key.

·         *C:\Windows\System32\config\SECURITY*: contains the security
information which is stored in the “HKLM\SECURITY” Key.

·         *C:\Windows\System32\config\SOFTWARE*: contains information about
the computer’s software configuration which is stored in the
“HKLM\SOFTWARE” Key.

·         *C:\Windows\System32\config\SYSTEM*: contains information about
the computer’s system configuration which is stored in the “HKLM\SYSTEM”
Key.

·         *C:\Users\[Username]\NTUSER.DAT*: contains the Registry settings
for an individual User account.






__._,_.___
------------------------------
Posted by: "Beowulf" <[email protected]>
------------------------------


Visit Your Group
<https://groups.yahoo.com/neo/groups/grendelreport/info;_ylc=X3oDMTJmczlqa282BF9TAzk3MzU5NzE0BGdycElkAzIwMTk0ODA2BGdycHNwSWQDMTcwNTMyMzY2NwRzZWMDdnRsBHNsawN2Z2hwBHN0aW1lAzE0NTYxNzEyOTQ->


[image: Yahoo! Groups]
<https://groups.yahoo.com/neo;_ylc=X3oDMTJlc2hiOGdpBF9TAzk3NDc2NTkwBGdycElkAzIwMTk0ODA2BGdycHNwSWQDMTcwNTMyMzY2NwRzZWMDZnRyBHNsawNnZnAEc3RpbWUDMTQ1NjE3MTI5NQ-->
• Privacy <https://info.yahoo.com/privacy/us/yahoo/groups/details.html> •
Unsubscribe <[email protected]?subject=Unsubscribe>
• Terms of Use <https://info.yahoo.com/legal/us/yahoo/utos/terms/>

__,_._,___

-- 
-- 
Thanks for being part of "PoliticalForum" at Google Groups.
For options & help see http://groups.google.com/group/PoliticalForum

* Visit our other community at http://www.PoliticalForum.com/  
* It's active and moderated. Register and vote in our polls. 
* Read the latest breaking news, and more.

--- 
You received this message because you are subscribed to the Google Groups 
"PoliticalForum" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
For more options, visit https://groups.google.com/d/optout.

Reply via email to