F 220: Capturing and Examining the Registry
Computer forensics 1Educational 53tutorial 30 Autopsy forensics FTK Imager RecentDocs registry analysis RegRipper TypedURLs USBSTOR UserAssist
Instructional tutorial video demonstrating how to capture and analyze the Windows Registry using FTK Imager and Autopsy. Covers viewing TypedURLs, UserAssist, RecentDocs, determining CurrentControlSet, examining USBSTOR entries, and using RegRipper to extract recent document information.