Deleted registry hi...
 
Notifications
Clear all

Deleted registry hives

9 Posts
6 Users
0 Reactions
550 Views
nightworker
(@nightworker)
Estimable Member
Joined: 16 years ago
Posts: 134
Topic starter  

This case it manager who cloned company hard drive is this evidence support my opinions?
What i sould understrand from this case


   
Quote
jaclaz
(@jaclaz)
Illustrious Member
Joined: 18 years ago
Posts: 5133
 

This case it manager who cloned company hard drive is this evidence support my opinions?

I guess it depends on WHAT exactly are your opinions. ?

Those entries are connected with Optional Packages of a PE 4.x/5.x
https://technet.microsoft.com/en-us/library/hh824926.aspx

Which may mean that on that machine the Windows 8/8.1 ADK has been installed or downloaded, but not much more.

jaclaz


   
ReplyQuote
nightworker
(@nightworker)
Estimable Member
Joined: 16 years ago
Posts: 134
Topic starter  

thanks to feedback


   
ReplyQuote
EricZimmerman
(@ericzimmerman)
Estimable Member
Joined: 13 years ago
Posts: 222
 

what program did you use to recover those? =)


   
ReplyQuote
EricZimmerman
(@ericzimmerman)
Estimable Member
Joined: 13 years ago
Posts: 222
 

also those arent deleted hives, they are deleted KEYS.


   
ReplyQuote
(@belkasoft)
Estimable Member
Joined: 17 years ago
Posts: 169
 

To look for registy files, including deleted and badly damaged ones, you can use Belkasoft Evidence Center (http//belkasoft.com/ec). You can also use built-in carving tool to recover the data.
Here is a short video tutorial on how to do it, and what can be found
https://www.youtube.com/watch?v=WnmQ-_42IYQ


   
ReplyQuote
(@twjolson)
Honorable Member
Joined: 17 years ago
Posts: 417
 

also those arent deleted hives, they are deleted KEYS.

Well, sure, if you want to get all technical…


   
ReplyQuote
UnallocatedClusters
(@unallocatedclusters)
Honorable Member
Joined: 13 years ago
Posts: 576
 

Nightworker,

You said "This case it manager who cloned company hard drive is this evidence support my opinions? What i sould understrand from this case"

Do you mean, "I am analyzing a forensic image of a computer of a former IT manager to determine if IT manager created a copy of the computer, possibly using some version of WindowsPE/FE to do it, before leaving the organization."?


   
ReplyQuote
EricZimmerman
(@ericzimmerman)
Estimable Member
Joined: 13 years ago
Posts: 222
 

This is forensics. our world is technical =)


   
ReplyQuote
Share: