A Presentation on Registry forensics from one of my lectures. Thanks to Harlan Carvy and Jolanta Thomassen for wonderful researches in the field. The work is based on their researches
7. Mapping the Registry file BCD (Boot configuration data replaced Boot configuration {Boot.ini} in Vista and onwards USRCLASS.DAT is merged with NTUSER.DAT when the user logs in to provide complete configuration
28. Is that all?????? Its just the start……… Q&A My Info [email_address] Twitter: http:// twitter.com/boonlia Facebook: http://www.facebook.com/profile.php?id=1701055902