SavitarX
search
Ctrlk
LinkedinTryHackme
  • README
  • CERTIFICATIONS & notes
    • My Roadmap to Becoming a Penetration Tester & Red Team
    • Comp Networkchevron-right
    • Red Teamchevron-right
    • Blue Teamchevron-right
      • SOC Analystchevron-right
      • DFIRchevron-right
        • Introduction to Digital Forensics
        • Investigating Windows Endpointschevron-right
          • Windows Event Logschevron-right
          • The Registrychevron-right
            • NTUSER.DAT
            • UsrClass.dat & ShellBags
            • USB Forensics
          • Evidence of Executionchevron-right
          • Persistence and Lateral Movementchevron-right
          • Anatomy of NTFSchevron-right
          • File Deletion and Recoverychevron-right
          • LNK Files and Jump Listschevron-right
          • User Behavior Forensicschevron-right
        • Investigating Windows Memory
        • Investigating Linux Devices
        • MacOS Forensics
    • Web Pentestingchevron-right
  • Writeups
    • Tryhackmechevron-right
    • HTB Sherlockschevron-right
  • Machines to pratice for
    • CPTS Preparation
    • CDSA Preparation
    • OSEP
  • The Computer Science and Engineering program
    • Read this
    • Computer Sciencechevron-right
    • Securitychevron-right
gitbookPowered by GitBook
block-quoteOn this pagechevron-down
  1. CERTIFICATIONS & noteschevron-right
  2. Blue Teamchevron-right
  3. DFIRchevron-right
  4. Investigating Windows Endpoints

The Registry

NTUSER.DATchevron-rightUsrClass.dat & ShellBagschevron-rightUSB Forensicschevron-right
PreviousEvent Logs Cheat Sheetchevron-leftNextNTUSER.DATchevron-right