http://www.forensicmag.com/articles/2015/07/windows-10-registry-forensics-overview ?
Windows 10 Registry Forensics: An Overview Wed, 07/22/2015 - 2:28am John J. Barbara Digital Forensics Consulting, LLC <http://www.forensicmag.com/company-profiles/digital-forensics-consulting-llc> Get today's news and top headlines for forensics professionals - Sign up now! <http://subscriptions.forensicmag.com/?cmpid=textadincontent> Over the last decade or so, computers have virtually taken over control of every facet of modern civilization. Every person who uses a computer at their workplace takes for granted that computers are essential in the work environment. They store or can access all the information necessary for normal day-to-day business operations. But there is a dark side to computer use, or rather computer misuse. Regardless of how many written rules, policies, and procedures management puts into place to protect the confidentiality and integrity of their digital information and intellectual property, it seems inevitable that a breach will eventually occur. Often the breach happens when an employee intentionally disregards policy and attaches a USB device to their workplace computer. Although their intent may be just to upload some pictures to display as a desktop slide show, they could also download proprietary information. Likewise, they could unintentionally or intentionally infect the computer with one or more of the thousands of computer viruses that currently exist. *The Problem in Perspective* Consider the following: Presume that an employee attaches a USB device to his workplace computer at the end of the day intending to download the company’s customer database which contains thousands of names, addresses, phone numbers, credit card numbers and so forth. After the download completes, he removes the USB device and turns off the computer. Unknowingly to him, a co-worker observed him attaching and removing the USB device. Since the workday was over, the co-worker could not inform IT Security until the next day. When IT Security confronts the alleged perpetrator, he denies the allegation. How is management and IT Security going to handle this situation to either prove or disprove the allegation? Probably the best approach would be to perform an examination of the computer hard drive to look for probative information. Normally this involves forensically imaging the hard drive in a controlled environment with one of the many forensic imaging tools. Most forensic tools incorporate automated built-in features, such as, recovering deleted folders, performing keyword searches, carving data from unallocated space, searching directories and files and so forth. The image could then be examined further, focusing upon the Registry, searching for any USB devices that may have been attached to the computer. Often, however, business IT department members lack the necessary qualifications or experience to perform these types of forensic examinations. This is not uncommon since IT personnel normally are not trained as forensic examiners. Under these circumstances, management may have to contract with an external digital forensics consulting firm to provide the services. In today’s digital forensics environment, examiners must have specialized training, knowledge, skills, abilities, tools and experience to ensure reliable and repeatable results when triaging a live system or examining a computer hard drive* post-mortem*. Regardless, it is essential in today’s business environment that management has a well-documented action plan in place such that if a breach occurs, or employee misconduct is alleged, they will have a firm foundation to support and assist with any potential civil or criminal proceedings. Failure to do so can have a detrimental effect upon the business or corporation. *What is the Windows Registry?* A typical Windows OS has many forensically important areas where probative information can be found, such as in RAM (live system) or stored somewhere on the computer’s hard drive. Any examination and extraction of probative information from a live system involves the use of triage tools which themselves will make changes to those same forensically important areas. Although this violates the “golden rule” of digital forensics, in some circumstances there is no alternative. However, before doing so, an examiner must have previously verified the functionality of the triage tools and know what changes are made to a live system when those tools are used. The Registry, which is a goldmine of potential probative information, evolved over the years from the early Windows operating systems ‘WIN.INI’ and ‘SYSTEM.INI’ files. When Windows 3.1 was introduced, it was initially targeted to the corporate work environment and used individual ‘.ini’ human readable text files which were linked to the ‘WIN.INI’ file. With the release of Windows 95, the Registry as we know it today was introduced. [image: Description: Figure 1]Figure 1The Microsoft Computer Dictionary, Fifth Edition, defines the Registry as: “A central hierarchical database used in Microsoft Windows 9x, Windows CE, Windows NT, and Windows 2000 used to store information that is necessary to configure the system for one or more user’s applications and hardware devices.” Windows XP, Windows Vista, Windows 7, and Windows 8 all included a Registry. The soon to be released Windows 10 also contains a Registry and will be the focus of this and several future columns. (Data relating to the Windows 10 Registry was obtained from Windows Evaluation Build 9841). Some examples of the information contained within the Registry which Windows 10 must continually reference to function includes: · USB storage devices that have been attached to the computer. · Wireless networks that the computer has connected to. · Recent search terms. · Lists of the most recently used files or applications. · Autorun locations which list applications to run when the computer is booted. · Contents of the User(s) desktop. · Malware (if it has installed itself as a service). *[image: Description: Figure 2]**Figure 2Where is the Information Stored?* The Windows 10 Registry is not in actuality a central hierarchical database or one large fi le, but rather a set of files referred to as ‘Hives.’ These files, located in the “C:\Windows\System32\config” and “C:\Users\[Username]\” directories, are updated each time a User logs onto the computer and are shown in Figures 1 and 2. Their contents are as follows: · *C:\Windows\System32\config\DEFAULT*: contains the default system information which is stored in the “HKEY_USERS\.DEFAULT” Key. · *C:\Windows\System32\config\SAM*: contains information about the Security Accounts Manager (SAM) service which is stored in the “HKLM\SAM” Key. · *C:\Windows\System32\config\SECURITY*: contains the security information which is stored in the “HKLM\SECURITY” Key. · *C:\Windows\System32\config\SOFTWARE*: contains information about the computer’s software configuration which is stored in the “HKLM\SOFTWARE” Key. · *C:\Windows\System32\config\SYSTEM*: contains information about the computer’s system configuration which is stored in the “HKLM\SYSTEM” Key. · *C:\Users\[Username]\NTUSER.DAT*: contains the Registry settings for an individual User account. __._,_.___ ------------------------------ Posted by: "Beowulf" <[email protected]> ------------------------------ Visit Your Group <https://groups.yahoo.com/neo/groups/grendelreport/info;_ylc=X3oDMTJmczlqa282BF9TAzk3MzU5NzE0BGdycElkAzIwMTk0ODA2BGdycHNwSWQDMTcwNTMyMzY2NwRzZWMDdnRsBHNsawN2Z2hwBHN0aW1lAzE0NTYxNzEyOTQ-> [image: Yahoo! Groups] <https://groups.yahoo.com/neo;_ylc=X3oDMTJlc2hiOGdpBF9TAzk3NDc2NTkwBGdycElkAzIwMTk0ODA2BGdycHNwSWQDMTcwNTMyMzY2NwRzZWMDZnRyBHNsawNnZnAEc3RpbWUDMTQ1NjE3MTI5NQ--> • Privacy <https://info.yahoo.com/privacy/us/yahoo/groups/details.html> • Unsubscribe <[email protected]?subject=Unsubscribe> • Terms of Use <https://info.yahoo.com/legal/us/yahoo/utos/terms/> __,_._,___ -- -- Thanks for being part of "PoliticalForum" at Google Groups. For options & help see http://groups.google.com/group/PoliticalForum * Visit our other community at http://www.PoliticalForum.com/ * It's active and moderated. Register and vote in our polls. * Read the latest breaking news, and more. --- You received this message because you are subscribed to the Google Groups "PoliticalForum" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. For more options, visit https://groups.google.com/d/optout.
