Deleted registry hi...
 
Notifications
Clear all

Deleted registry hives

9 Posts
6 Users
0 Reactions
759 Views
nightworker
(@nightworker)
Estimable Member
Joined: 17 years ago
Posts: 134
Topic starter   [#13053]

This case it manager who cloned company hard drive is this evidence support my opinions?
What i sould understrand from this case



   
Quote
jaclaz
(@jaclaz)
Illustrious Member
Joined: 19 years ago
Posts: 5133
 

This case it manager who cloned company hard drive is this evidence support my opinions?

I guess it depends on WHAT exactly are your opinions. ?

Those entries are connected with Optional Packages of a PE 4.x/5.x
https://technet.microsoft.com/en-us/library/hh824926.aspx

Which may mean that on that machine the Windows 8/8.1 ADK has been installed or downloaded, but not much more.

jaclaz



   
ReplyQuote
nightworker
(@nightworker)
Estimable Member
Joined: 17 years ago
Posts: 134
Topic starter  

thanks to feedback



   
ReplyQuote
EricZimmerman
(@ericzimmerman)
Estimable Member
Joined: 13 years ago
Posts: 222
 

what program did you use to recover those? =)



   
ReplyQuote
EricZimmerman
(@ericzimmerman)
Estimable Member
Joined: 13 years ago
Posts: 222
 

also those arent deleted hives, they are deleted KEYS.



   
ReplyQuote
Belkasoft
(@belkasoft)
Joined: 17 years ago
Posts: 169
 

To look for registy files, including deleted and badly damaged ones, you can use Belkasoft Evidence Center (http//belkasoft.com/ec). You can also use built-in carving tool to recover the data.
Here is a short video tutorial on how to do it, and what can be found
https://www.youtube.com/watch?v=WnmQ-_42IYQ



   
ReplyQuote
(@twjolson)
Honorable Member
Joined: 17 years ago
Posts: 417
 

also those arent deleted hives, they are deleted KEYS.

Well, sure, if you want to get all technical…



   
ReplyQuote
UnallocatedClusters
(@unallocatedclusters)
Honorable Member
Joined: 14 years ago
Posts: 576
 

Nightworker,

You said "This case it manager who cloned company hard drive is this evidence support my opinions? What i sould understrand from this case"

Do you mean, "I am analyzing a forensic image of a computer of a former IT manager to determine if IT manager created a copy of the computer, possibly using some version of WindowsPE/FE to do it, before leaving the organization."?



   
ReplyQuote
EricZimmerman
(@ericzimmerman)
Estimable Member
Joined: 13 years ago
Posts: 222
 

This is forensics. our world is technical =)



   
ReplyQuote
Share: