Google Groups no longer supports new Usenet posts or subscriptions. Historical content remains viewable.
Dismiss

Windows Registry Forensics

2 views
Skip to first unread message

techie phone

unread,
Jun 29, 2009, 11:59:59 PM6/29/09
to

How does one backup the registry for off line forensics analysis. Some
tutorials advise to export from the regedit.exe program. I tried this
method and ended up with a 224 meg file. I plan on using regripper 2.02,
the open source software. Suggestions are welcome.

thank you.

John John - MVP

unread,
Jun 30, 2009, 8:56:37 AM6/30/09
to

Being that forensic tools are usually used on dead or 'sleeping'
installations your registry tool should just be able to open the
registry files in the WINNT\system32\config folder. If you want to
create a backup you can select to backup the registry when you create an
Emergency Repair Disk and a backup will be stored in the
\WINNT\repair\RegBack folder.

John

0 new messages