XML conversion of the windows registry for forensic processing and distribution

7Citations
Citations of this article
12Readers
Mendeley users who have this article in their library.

This article is free to access.

Abstract

The Windows Registry often contains key data that help determine the activities performed on a computer. While some forensic tools format Registry data for common questions that are required to be answered in digital investigations, their output is geared for standalone use, not for indexable content. This paper describes RegXML, an XML syntax designed to represent Windows Registry hive files. RegXML captures the logical structure of a hive and notes the locations of found data within hive files. The paper also describes a Python library designed to be used with RegXML and the results obtained upon applying the library to analyze two forensic corpora. Experimental results are presented based on hundreds of disk images, thousands of hive files and tens of millions of Registry cells. © 2012 IFIP International Federation for Information Processing.

Cite

CITATION STYLE

APA

Nelson, A. (2012). XML conversion of the windows registry for forensic processing and distribution. In IFIP Advances in Information and Communication Technology (Vol. 383 AICT, pp. 51–65). https://doi.org/10.1007/978-3-642-33962-2_4

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free