The Windows Registry as a forensic artefact: Illustrating evidence collection for Internet usage

V Mee, T Tryfonas, I Sutherland - Digital Investigation, 2006 - Elsevier
In this paper we examine the use of the Windows Registry as a source of forensic evidence
in digital investigations, especially related to Internet usage. We identify the sources of the
information, along with the methods used and toolsets available for such examinations, and
illustrate their use for recovering evidence. We highlight issues of the forensic practise
related to Registry inspections and propose ideas for further improvements of the process
and the tools involved.
以上显示的是最相近的搜索结果。 查看全部搜索结果