Disk Analysis Introduction
Last updated
Last updated
Let's drop the registry hives into Registry Explorer.
Next, let's extract some system information from these registry hives using Registry Explorer and RegRipper.
Computername: Registry: HKLM\System\CurrentControlSet\Control\Computername\
Windows Version: Registry: HKLM\Software\Microsoft\Windows NT\Currentversion\
Let's use RegRipper, but first, copy the registry hives to a separate folder.
Timezone: Registry: HKLM\System\CurrentControlSet\Control\TimeZoneInformation\
Network Information: Registry: HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{interface-name}
Shutdown time: Registry: HKLM\System\ControlSet001\Control\Windows\ShutdownTime
Defender settings: Registry: HKLM\Software\Microsoft\Windows Defender\
The files UsrClass.dat and NTUSER.DAT are hidden. Let’s display them.
Let's process each hive using RegRipper.
Let's open them in Notepad.
Let's use Ctrl + F to search for the shutdown time, then select "Find All in All Opened Document."