RegAnalyzer Tool to Automate Windows 7 Registry Forensics Analysis
Main Article Content
Abstract
Use of computers for performing crimes is increasing day by day. It has become necessary for investigator to collect evidences from suspect’s computer. Windows 7 has become mainstream operating system for users and thus its forensics investigation is becoming important. One of the areas of interest is windows registry. It contains valuable information that can be helpful for the forensics analysis. Registry contains the basic information like date when Operating System installed, owner name and the advanced information such as the software and hardware devices installed on system, storage devices attached to system, services running on system, history of recently used documents and so on, which will help the analyst to decide the way of further analysis of system depending on the its environment. Though it has such valuable information it is very difficult for an analyst to manually search and analyze it to collect evidences because of its complex structure. So in this paper we presented details of Windows 7 registry, its use for forensic analysis and proposed design for a tool (RegAnalyzer) which will automate task of windows 7 registry analysis for forensics investigator so he/she can use it for the further investigation of system.
Â
Â
Keywords: computer forensics; registry forensics; registry structure; windows 7 forensics; windows registry
Downloads
Article Details
COPYRIGHT
Submission of a manuscript implies: that the work described has not been published before, that it is not under consideration for publication elsewhere; that if and when the manuscript is accepted for publication, the authors agree to automatic transfer of the copyright to the publisher.
Authors who publish with this journal agree to the following terms:
- Authors retain copyright and grant the journal right of first publication with the work simultaneously licensed under a Creative Commons Attribution License that allows others to share the work with an acknowledgment of the work's authorship and initial publication in this journal.
- Authors are able to enter into separate, additional contractual arrangements for the non-exclusive distribution of the journal's published version of the work (e.g., post it to an institutional repository or publish it in a book), with an acknowledgment of its initial publication in this journal.
- Authors are permitted and encouraged to post their work online (e.g., in institutional repositories or on their website) prior to and during the submission process, as it can lead to productive exchanges, as well as earlier and greater citation of published work
- The journal allows the author(s) to retain publishing rights without restrictions.
- The journal allows the author(s) to hold the copyright without restrictions.