The Windows Registry as a forensic artefact: Illustrating evidence collection for Internet usage

  • Authors:
  • Vivienne Mee;Theodore Tryfonas;Iain Sutherland

  • Affiliations:
  • Information Security Research Group, School of Computing, University of Glamorgan, Pontypridd, Wales, CF37 1DL, United Kingdom;Information Security Research Group, School of Computing, University of Glamorgan, Pontypridd, Wales, CF37 1DL, United Kingdom;Information Security Research Group, School of Computing, University of Glamorgan, Pontypridd, Wales, CF37 1DL, United Kingdom

  • Venue:
  • Digital Investigation: The International Journal of Digital Forensics & Incident Response
  • Year:
  • 2006

Quantified Score

Hi-index 0.00

Visualization

Abstract

In this paper we examine the use of the Windows Registry as a source of forensic evidence in digital investigations, especially related to Internet usage. We identify the sources of the information, along with the methods used and toolsets available for such examinations, and illustrate their use for recovering evidence. We highlight issues of the forensic practise related to Registry inspections and propose ideas for further improvements of the process and the tools involved.