Advanced
Advanced

Registry Analysis

In "Registry Analysis", you will learn the knowledge of the registry and the analysis method required for forensic investigation based on the forensic investigation that FRONTEO has experienced so far.

Curriculum

On the 1th day,

  1. Registry analysis overview
  2. Basics of registry analysis
  3. Registry collection from a live system
  4. SAM registry analysis
    • User account information
  5. SYSTEM registry analysis
    • About Control Sets
    • Individual identification and connection history of externally connected devices

On the 2th day,

  1. SOFTWARE registry analysis
    • Information about Windows
    • Installed program information
    • Traces of wireless connection
  2. NTUSER.DAT registry analysis
    • Differences from SOFTWARE Hive
    • Various traces of individual user behavior
  3. Other items related to the registry

* Each schedule will be from 9:30 to 17:00.
* Curriculum is subject to change.Please check when making inquiries.

Detailed information

Course target
  • Basic knowledge of computer forensics
  • Those who understand the basic operation of personal computers (especially Windows)
  • Those who have passed the IT Passport Examination (old: Elementary System Administrator Examination) or those who have equivalent knowledge and skills

* If you are unsure about your skills, we recommend that you take Digital Forensic Preservation Practice and Digital Forensic Analysis Basics in advance.

Knowledge skills that can be acquiredRegistry knowledge and analysis methods required for forensic surveys based on FRONTEO's actual survey experience.
Tuition feePlease contact us.