Finding Information in the Software Key

The information found in the Software key (HKLM\SOFTWARE) is located in a file named software, as shown in Figure 9-1. This file is found in the path %SystemRoot%\system32\config and should not be confused with the Software key found in the HKEY_CURRENT_USER key, abbreviated HKCU. The HKLM\SOFTWARE key contains software settings for the local machine, while HKCU\Software contains software settings that are user specific. Although both are important, our current focus is on the local machine software settings.

Figure 9-1: Location of the software hive file in the path %SystemRoot%\system32\config

c09f001.tif

Installed ...

Get Mastering Windows Network Forensics and Investigation, 2nd Edition now with O’Reilly online learning.

O’Reilly members experience live online training, plus books, videos, and digital content from 200+ publishers.