2 - Windows Forensics.pdf

Here’s a compact summary of the second set of slides on Windows Forensics II:

  1. Registry Forensics:

    The Windows registry stores key system and user data in different “hives” such as:

    Located on disk: C:\Windows\system32\config

  2. Event Logs:

  3. Link Files:

  4. Prefetch Files:

  5. Thumbnail Cache:

  6. Recycle Bin:

  7. External Devices:

  8. Pagefile and Hibernation Files:

  9. Restore Points and Shadow Copies:

These slides continue from the first set, diving deeper into Windows artefacts, focusing on forensic techniques to analyze user actions, system logs, and connected devices.