If the MFT is the “City Map” of the file system, the Windows Registry is the Central Nervous System and Genetic Database of the entire operating system. For a forensic investigator, the Registry is a goldmine that records every configuration change, every software installation, every hardware device ever plugged in, and most importantly, the habits and tracks of the user.
The Registry is not a single file; it is a complex, hierarchical database that stores settings for the hardware, software, and users. In this lecture, we will dissect the Registry’s architecture, the primary “Hives” of forensic interest, and the specific keys that reveal an attacker’s presence.
1. The Hierarchical Architecture: Hives, Keys, and Values
To understand the Registry, you must understand its structure. It is organized like a file system but exists as a set of binary files called Hives.
- Hives: These are the actual binary files stored on the disk (e.g.,
SYSTEM,SOFTWARE,SAM,SECURITY, andNTUSER.DAT). - Keys and Subkeys: These are like “Folders” within the hives.
- Values: These are the “Files” within the keys. A value has a Name, a Data Type (like
REG_SZfor strings orREG_DWORDfor numbers), and the Data itself.
2. The Five Master Root Keys
When you open regedit.exe on a live system, you see five root keys. However, in forensics, we know that some of these are merely “links” created in RAM during bootup.
- HKEY_CLASSES_ROOT (HKCR): Stores file associations and OLE information.
- HKEY_CURRENT_USER (HKCU): Contains the settings for the user currently logged in. (Forensic source:
NTUSER.DAT). - HKEY_LOCAL_MACHINE (HKLM): Contains settings for the entire machine (hardware and system-wide software). (Forensic source:
SYSTEM,SOFTWARE,SAM,SECURITY). - HKEY_USERS (HKU): Contains profiles for all users on the machine.
- HKEY_CURRENT_CONFIG (HKCC): Information about the hardware profile used at startup.
3. Forensic Hive Locations (Where the Evidence Lives)
To analyze the Registry “offline” (on a forensic image), you must know where these binary hive files are physically located.
- System-wide Hives: Located in
%SystemRoot%\System32\config\SYSTEM: Hardware, drivers, and services.SOFTWARE: Installed applications and OS configuration.SAM(Security Accounts Manager): Local user accounts and hashed passwords.SECURITY: System-wide security policies.
- User-Specific Hives: *
NTUSER.DAT: Located inC:\Users\<username>\. This records the unique actions of that specific user.USRCLASS.DAT: Located inC:\Users\<username>\AppData\Local\Microsoft\Windows\. Stores user-specific file associations and Shell Item information.
4. The “Persistence” Hunt: Where Malware Hides
Malware’s primary goal after infection is Persistence—ensuring it starts up again after a reboot. The Registry is the most common place to achieve this.
A. The “Run” and “RunOnce” Keys
These are the classic hiding spots. Any path listed here will execute when a user logs in.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunHKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
B. Services and Drivers
Sophisticated malware installs itself as a system service to gain higher privileges.
HKLM\SYSTEM\CurrentControlSet\Services- Investigative Tip: Look for services with suspicious “ImagePath” entries pointing to
Tempfolders orUsers\Public.
- Investigative Tip: Look for services with suspicious “ImagePath” entries pointing to
C. AppInit_DLLs
This key allows a DLL to be loaded into every process that uses User32.dll (which is almost every GUI app). It is a powerful injection technique.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs
5. User Activity Tracking: The NTUSER.DAT Evidence
The NTUSER.DAT hive is a diary of the user’s life. If a suspect claims “I never opened that file,” the Registry will prove them wrong.
- UserAssist: This key tracks every GUI program a user has executed, how many times they ran it, and the last time it was launched. Note: The names are often ROT13 encrypted to hide them from casual viewing.
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist
- RecentDocs: A list of the most recently opened files by extension.
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs
- ShellBags: This is forensic magic. ShellBags record the window size, position, and view settings of every folder a user has ever opened—even if that folder was on a USB drive that is no longer plugged in.
HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags
6. Hardware and USB Forensics: The USBSTOR Key
Whenever a USB device is plugged in, Windows records the Vendor ID, Product ID, and the unique Serial Number of that device.
- The Key:
HKLM\SYSTEM\CurrentControlSet\Enum\USBSTOR - The Intelligence: By cross-referencing this with the
SYSTEMhive’sMountedDeviceskey, you can prove that a specific physical USB drive (with a specific serial number) was assigned to a specific drive letter (e.g.,E:) at a specific time.
7. Technical Procedure: Parsing the Hives
Registry hives are binary; you cannot read them with a text editor. We use professional tools to “parse” them into human-readable data.
- Extract the Hives: Use
KAPEorFTK Imagerto pull the files from the disk image. - Registry Explorer (Eric Zimmerman): The industry-standard GUI tool for manual exploration. It handles “Dirty Hives” by replaying the transaction logs (
.log1,.log2) to ensure you see the most recent data. - RECmd (Registry Entity Commander): A command-line tool used to search across multiple hives for specific keywords (like a suspect’s name or a malware’s IP address).
# Example RECmd command to search for 'Run' keys across all hives
RECmd.exe -d "C:\Forensics\Hives" --kn "Run" --csv "C:\Analysis\Output"8. The Registry Transaction Logs (Dirty Hives)
Windows is constantly writing to the Registry. If a computer is powered off abruptly, some data might still be in the .log files and not yet committed to the main hive file.
- Forensic Warning: If you only analyze the hive file without its corresponding
.log1and.log2files, you are missing the most recent (and often most incriminating) data. Professional tools automatically “merge” these during analysis.
Operator Intelligence Summary
- Focus Keyphrase: Windows Registry Forensic Analysis
- Tags: Registry Hives, Persistence Mechanisms, UserAssist, USBSTOR, ShellBags, Forensic Artifacts
The Registry doesn’t forget. It is the “Permanent Record” of the Windows world. By mastering its hives, you can reconstruct user intent, prove hardware connection, and find the malware’s hidden heartbeat.
Operator Intelligence Recap: The “Deep State” of the OS
By completing these two modules, you have mastered the two most complex databases in the Windows environment:
- The MFT (The Map): You now know how to look past the file names and into the raw MFT Records to find resident data and prove when an attacker has manually “backdated” their files using the 0x10/0x30 timestamp discrepancy.
- The Registry (The DNA): You have moved from viewing the Registry as a “settings menu” to seeing it as a historical log of human behavior. You can now prove exactly which USB drives were used, which folders were opened (even on deleted drives), and exactly how a piece of malware survives a system reboot.
