Registry Analysis
windowsir.blogspot.com·1d·
Flag this post

First off, what is “analysis”?

I submit that “analysis” is what happens when an examiner has investigative goals and context, and applies this, along with their knowledge and experience, to a data set. This can be anything, from a physical image of a mobile device, to a triage collection from an endpoint, to logs from a device, or various devices.

IMHO, this distinction is valuable, because what we often call “analysis” is really nothing more than parsing. For example, someone may recommend (or state as part of their process) that we open a Registry hive in a viewer, and navigate to a particular path by clicking through the UI. Now, there are ways that this could be accomplished in a much more efficient manner (I didn’t say “easier”, because the command line isn’t “easier” for som…

Similar Posts

Loading similar posts...