Question

In: Computer Science

Digital Forensics In detail, explain the Window’s registry. Describe its structure, its purpose, and how forensic...

Digital Forensics

In detail, explain the Window’s registry. Describe its structure, its purpose, and how forensic examiners can use it in a case. In addition, describe what metadata is and how it relates to digital forensics.

Solutions

Expert Solution

Windows system is working on registry without registry entry windows will not find the proper path of some installed application in short we can say registry is a index register like attendance register in our class where each entry tells student name and its seating location and absent present status, same way windows registry tells windows the status of startup services and its physical path of each execution services.

likewise you can see in the screenshot there are basically 5 categories , it is divided since win95 till its same structure remain in the win 10 also

HKEY_CLASSES_ROOT
HKEY_CURRENT_USER
HKEY_LOCAL_MACHINE
HKEY_USERS
HKEY_CURRENT_CONFIG

each has detailed sub-key in which system hardware configuration its driver status its version and many more information are stored even users are restricted using registry editor if only single bit 0 to 1 will be change then system tool may be blocked using users so its powerful tool for system management.

In digital forensic if you run registry editor monitor tool you will get to know that there are each process which keep registry setting open and close millions of time in background process so from that we can find the user activity that what he/she has opened .

if you have any doubt then please ask me without any hesitation in the comment section below , if you like my answer then please thumbs up for the answer , before giving thumbs down please discuss the question it may possible that we may understand the question different way and we can edit and change the answers if you argue, thanks :)


Related Solutions

A2Z Forensics is a digital forensics investigation firm that conducts forensic investigations for public as well...
A2Z Forensics is a digital forensics investigation firm that conducts forensic investigations for public as well as private sectors. You are working in this firm as a forensics specialist for a number of years now. The firm is establishing a new forensics lab to meet the future requirements. You have been asked to prepare a business case for this new lab. Your job is to focus on three aspects of the new lab which are hardware, software and lab security....
Digital Forensics, Please describe in detail in your own language Describe Linux their artifacts and their...
Digital Forensics, Please describe in detail in your own language Describe Linux their artifacts and their functionalities. How they might be used by forensic examiners?
Digital Forensics 1. Many anti-forensic techniques also have purposes which are not for anti-forensics. For each...
Digital Forensics 1. Many anti-forensic techniques also have purposes which are not for anti-forensics. For each of the following, describe the technique and what would be required to show there was intent to destroy or hide evidence. a. Encryption b. Defragmentation c. Drive Wiping
Explain what a Windows Registry Shellbag is and how it can be used during a forensic...
Explain what a Windows Registry Shellbag is and how it can be used during a forensic investigation.
Digital Forensics, Describe in your own language, at least 200 words for each question 1/Explain the...
Digital Forensics, Describe in your own language, at least 200 words for each question 1/Explain the Fourth Amendment and its impact on Digital Forensics 2/Define the Electronic Communication Privacy Act 3/Describe email protocols.
1. Pick an organelle from a plant cell and in detail, explain how its structure and...
1. Pick an organelle from a plant cell and in detail, explain how its structure and function are linked. (Do the Rough Endoplasmic Reticulum). 2. Is it a good idea for drug companies to develop weight-loss drugs that affect cellular respiration? Why or why not? (more than 50 word response)
Digital Forensics, at least 250 words Chapter 5 goes into great detail about Windows systems, however,...
Digital Forensics, at least 250 words Chapter 5 goes into great detail about Windows systems, however, other systems, such as Mac, Linux exist. Search for one other system not mentioned in your book and describe their artifacts and their functionalities. How they might be used by forensic examiners? Be sure to list your sources.
Describe the purpose of the cancer registry. Specify a minimum of ten data elements collected, excluding...
Describe the purpose of the cancer registry. Specify a minimum of ten data elements collected, excluding the patient name, address and date of birth. If there is central depository for any portion of the information collected, identify the agency/organization and include if this central depository is voluntary or required by law (Include the law citation). Articulate a state required data elements Articulate a state required submission time frames
what is SAFe? explain the essential level of SAFe in detail. Discuss the purpose, structure, elements...
what is SAFe? explain the essential level of SAFe in detail. Discuss the purpose, structure, elements of the essential level of SAFe.
Explain FLSA and its purpose. Then choose and explain in detail these two listed labor laws...
Explain FLSA and its purpose. Then choose and explain in detail these two listed labor laws below: Affordable Care Act (ACA) Migrant and Seasonal Agricultural Worker Protection Act Then, explain why labor laws are important to both the employee and the employer?
ADVERTISEMENT
ADVERTISEMENT
ADVERTISEMENT