regf
Every Registry file starts with a 4,096 byte header block. The first 512 […]
Every Registry file starts with a 4,096 byte header block. The first 512 […]
After reviewing several other sources, notably from Morgan and Norris, I’ve decided that […]
The first step to forensic analysis of the Registry is knowing where […]
Searching for information about the innards of the Registry returns a whole […]
There are a plethora of keys in the Registry dedicated to telling […]
For many years now I’ve tried to do all my live collection […]
These are useful command lines that are all based on built-in Windows […]
As I was putting together the list of command line tools to […]
There is no contesting that the command line in a Linux/Mac environment […]
I was asked not too long ago about how to extract metadata […]
Plist files are found sprinkled throughout OS X and iOS and contain the various configuration settings and other information of use to the OS and applications.