Cover of Windows Registry Forensics with Volatility Framework | Kapil Soni by Kapil Soni

Digital Forensics · 2014

Windows Registry Forensics with Volatility Framework | Kapil Soni

3rd Edition

Windows Registry Forensics with Volatility Framework is a hands-on guide to one of the richest evidence sources on any Windows system. It covers the structure of the registry, the artifacts that matter in an investigation, and how to extract them both from disk and from memory images using the Volatility Framework. Written for investigators who want repeatable technique over theory, it turns the registry into a reliable timeline of user and system activity.

What you'll learn

  • How the Windows Registry is structured and where evidence hides
  • Key registry artifacts for user activity, execution, and persistence
  • Recovering registry data from memory images with Volatility
  • Building an investigative timeline from registry artifacts

Who it's for

Digital forensics analysts, incident responders, and students of memory and Windows forensics.

Portrait of Kapil Soni

Kapil Soni

Bug bounty hunter, penetration tester, and vulnerability researcher.

Bug bounty hunter, penetration tester, and vulnerability researcher. Founder of Xowia Technologies. In infosec since 2012.

Own the edge, not just the book

Join the list for new-release notes and a free practitioner resource.