Even though I covered some here, there’s a lot more stuff that will be of interest to an investigator. As I mentioned before, this hive will have the device config data that is used for the control of the system startup. There are two sets – ControlSet001 and ControlSet002, within the SYSTEM hive. As you can see, Registry Explorer will even give you the ControlSet – Control Set is basically the hive that keeps the device configuration data that’s used for the control of the system startup. I am sure there are many tools out there, created specifically for this purpose, and please feel free to search for them.
- Blue screen of death, as known as BSOD, is a system error.
- As such, analysts need to have some familiarity with the Registry, and what can be found within the various hive files.
- This hive records information about system hardware and is created each time the system boots and performs hardware detection.
- In Windows XP , the permissions of the registry can block you from editing certain keys.
Then this stack is used to produce cumulative information about the layered key. Layered keys were introduced in Insider Preview builds of Windows 10 “Redstone 1” https://windll.com/dll/microsoft-corporation/winsta.
Registry Structure
Proper user authentication can be given to the systems to use the registry to not be leaked. The issue is not with the philosophy of registry but with it’s design. The registry is used by the OS to lookup important information regarding the program being loaded.
So it’s always advisable to back up your Registry files before using the editor. See the sidebar Backing up and Restoring for information on how to do this.
The Windows Registry
Windows Registry is a database of settings, information, configurations, options, and other values for hardware and software components installed on a Microsoft Windows platform. Once a program is installed, a subkey is generated in the registry. This subkey has information about the program, including the version, location, and other primary executable files. The policy editor loads the settings it can change from .ADM files, of which one is included, that contains the settings the Windows shell provides. The .ADM file is plain text and supports easy localisation by allowing all the strings to be stored in one place.
Leave a comment
Your email address will not be published. Required fields are marked *