Windows Registry Forensics

Analyze Windows Registry hives for forensic investigations. Use this skill whenever you need to extract system information, user activity, USB device history, network configurations, or timeline data from Windows Registry files (SYSTEM, NTUSER.DAT, USRCLASS.DAT, SOFTWARE). Trigger this skill for any Windows forensics task involving registry analysis, malware persistence detection, user activity reconstruction, or incident response investigations.

abelrguezr Updated

File contents

abelrguezr/hacktricks-skills/tree/main/skills/generic-methodologies-and-resources/basic-forensic-methodology/windows-forensics/interesting-windows-registry-keys commit 95414afcea

Frequently asked questions

npx skillmds@latest add abelrguezr/windows-registry-forensics