What tool for Registry forensics ?


  1. Posts : 34
    windows 7 Professional x64
       #1

    What tool for Registry forensics ?


    I currently have a win 7 machine that I need to find information stored in the
    registry (probably SAM-keys etc thats not available for a user mode)


    And btw, I did a full sector-by-sector clone of a C:/drive to .dd file so I probably need a
    so called offline tool to examine the register. If thats possible, I will also try a live-tool right now because time is son running out


    (the .dd file is a complete disk image as the state-of- saved as a original, and this is duplicated to copies for later examinations without affecting the real system)




    IĀ“dont have licensed Encase/forensic suits.
    But there are some open-source tools out there


    Regripper - ForensicsWiki


    https://www.researchgate.net/publica...ows_7_Registry

    Anyone with some tips?

    Code:
    Examples of data I want is the history, autologin,credentials, last network info, etc
    
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\Nla\Cache\Intranet
    
    
    
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\Signatures\Unmanaged
    
    
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\Profiles\{Wireless - Identifier}
    
    
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Printers
    
    
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\USBSTOR
      My Computer


  2. Posts : 3,786
    win 8 32 bit
       #2

    You don't say what you are actually looking for without that it's hard to say
      My Computer


  3. Posts : 34
    windows 7 Professional x64
    Thread Starter
       #3

    I/E credentials
    I/E autologins
    I/E history
    I/E downloaded files -source URL - (found 2 links when typing this)

    *that gave me lot of info about the webmail visited and info about that client,inbox strucutre etc



    USB devices
    Internet /home network



    You know....these kind of things:



    HKEY_USERS\S-1-5-21-[User Identifier] \Software\Microsoft\Internet Explorer\TypedURLs



    HKEY_USERS\S-1-5-21-[User Identifier] \Software \Microsoft \Windows\CurrentVersion\Explorer\Map Network Drive MRU

    HKEY_USERS\S-1-5-21-[User Identifier] \Software \WinRAR \ArcHistory






    HKEY_USERS\S-1-5-21-[User Identifier] \Software \Microsoft \Windows\CurrentVersion\Explorer\RecentDocs\.zip



    HKEY_USERS\S-1-5-21-[User Identifier] \Software \Microsoft \Windows\CurrentVersion\Explorer\RecentDocs\.zip



    HKEY_USERS\S-1-5-21-[User Identifier] \Software \Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.txt



    HKEY_USERS\S-1-5-21-[User Identifier] \Software \Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.jpg




    HKEY_USERS\S-1-5-21-[User Identifier] \Software \Microsoft \Windows\CurrentVersion\Explorer\RunMRU
      My Computer


  4. Posts : 3,615
    Win 10 x64, Linux Lite, Win 7 x64, BlackArch, & Kali
       #4

    Take a look at Nir Sofer's website, plethora of free tools.
    NirSoft
      My Computer


  5. Posts : 0
    Windows 7 Ultimate x64
       #5

    I suppose Hiren's Bootcd could load the registry hives. Tools at the Nirsoft site could do it too.
      My Computer


  6. Posts : 3,786
    win 8 32 bit
       #6

    We don't know why you want to do this as it may be a criminal offence
      My Computer


  7. Posts : 34
    windows 7 Professional x64
    Thread Starter
       #7

    F22 Simpilot said:
    I suppose Hiren's Bootcd could load the registry hives. Tools at the Nirsoft site could do it too.
    I did not find any in my Hireens USB-stick.
    (But thats an old version)



    Snick said:
    Take a look at Nir Sofer's website, plethora of free tools.
    NirSoft
    Ok thanks.


    I“ continue searching and will examine the disk_image that I took.
      My Computer


  8. Posts : 16,154
    7 X64
       #8

    Why not use regedit?
      My Computers


  9. Posts : 34
    windows 7 Professional x64
    Thread Starter
       #9

    SIW2 said:
    Why not use regedit?

    Why not read ?

    https://www.researchgate.net/publica...ows_7_Registry


    I am no expert, but I covered enough of information last 5 years of this matter to know that its a little more than that, when it comes to information stored in the windows registry.


    Some whitepapers, and real forensic reports from actual crime cases and also the research analys linked in this very thread shows that there is lots of data,thats not available with regedit.


    There is some values, that simply cant read from a live system at all.
    nur from a user-mode request on a windows system...





    Therefore, of that reason mentioned, some tools (like AccessData Registry viewer )
    FTK Toolkit and more utilitys exists, used and created by professional forensic engineers.





    Imgur: The magic of the Internet

    or should they instead call you and use regedit ?
    Last edited by rihtt; 14 Nov 2018 at 12:20. Reason: THIS FORUM SUCKS WHEN IT COMES TO EMBED IMAGES
      My Computer


  10. Posts : 16,154
    7 X64
       #10

    It is an entirely reasonable response to your preceding post #7.

    If you can spare a moment from being a jerk, you could see if running regworkshop in winpe will do what you want.

    Registry Workshop | www.torchsoft.com
      My Computers


 

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 06:33.
Find Us