Cyber Forensic Investigation—A Hunt for Windows Registry
摘要
In contemporary times, the extraction of digital proof from storage media is becoming an increasingly significant concern in digital forensics. This is primarily due to the intricate challenges associated with acquiring, preserving, and examining digital evidence, including time and space complexity considerations. Amidst these concerns, the analysis of the Microsoft Windows Registry has emerged as a valuable asset in the field of cyber forensics. Windows Registry analysis involves a systematic examination of the Windows Registry databases to identify any irregularities, shedding light on the precise processes involved in cybercrimes. The Windows Registry is a substantial source of digital evidence, comprising a database containing evidential information about the device and its users. Within the Windows Registry, one can discern traces of activities conducted on the device, with voluminous data related to various components of the host computer being stored. This paper studies and analyzes several prominent forensic tools designed for Windows Registry extraction. A comprehensive comparison of different cyber forensic tools covering diverse digital forensic domains like Windows, Image, Mobile, and Network forensics is provided. The main objective of the paper is to identify and evaluate the forensically relevant data that can be recovered using these tools. Furthermore, a scenario-based approach, illustrating the investigative process through a practical situation using an integrated digital forensic investigation process model, is presented. This allows for demonstrating the complete process from the discovery of evidence to the substantiation of findings with supporting documentation. Through this detailed examination, the paper aims to contribute valuable insights into the efficacy of digital forensic tools in the realm of Windows Registry analysis for cybercrime investigations.