[Webinar] Tracking User Behavior using the Windows Registry

February 29th, 1:00 pm - 2:00 pm ET
EDRM - Electronic Discovery Reference Model
Contact

EDRM - Electronic Discovery Reference Model

February 29th, 2024
1:00 PM - 2:00 PM ET

The Windows Registry has been around forever and is sometimes looked at as a HIVE of random chaos. However, even after all these years there is a lot of great information that can be pulled from the registry. This presentation is going to show investigators some key artifacts when working with the Registry (and other system files). Specifically, we will show file change activity allowing you to determine when files were edited or moved.

Join to learn:

  • Why should we still care about the Registry?
  • Why you should have remote collection abilities within your corporate network.
  • Can you collect from your company assets not connected to the company VPN?
  • Show the workflow of working with remote collection and the registry to monitor file change on an asset of interest.

Speaker:

Justin Tolman, Forensic Subject Matter Expert, Exterro

PRESENTED BY:

EDRM - Electronic Discovery Reference Model
Contact
more
less

EDRM - Electronic Discovery Reference Model on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide