The steps to be followed for Windows Registry analysis using Magnet AXIOM are as follows:
- Let's create a new case. Once it has been created and all the fields are filled in, go to evidence sources. Click the Load evidence button, and you will see the SELECT AN EVIDENCE SOURCE window, like the one in the following figure:
Figure 6.1. Magnet AXIOM SELECT AN EVIDENCE SOURCE window
- This time, let's choose the COMPUTER IMAGE option. Again, you can use one of the images you acquired in a previous recipe; both RAW and E01 are supported. Looking at the following figure, we can see that our image contains two partitions and an unpartitioned ...