O'Reilly logo

Windows Forensics Cookbook by Scar de Courcier, Oleg Skulkin

Stay ahead with the world's most comprehensive technology and business learning platform.

With Safari, you learn the way you learn best. Get unlimited access to videos, live online training, learning paths, books, tutorials, and more.

Start Free Trial

No credit card required

How to do it...

The steps to be followed for Windows Registry analysis using Magnet AXIOM are as follows:

  1. Let's create a new case. Once it has been created and all the fields are filled in, go to evidence sources. Click the Load evidence button, and you will see the SELECT AN EVIDENCE SOURCE window, like the one in the following figure:
Figure 6.1. Magnet AXIOM SELECT AN EVIDENCE SOURCE window
  1. This time, let's choose the COMPUTER IMAGE option. Again, you can use one of the images you acquired in a previous recipe; both RAW and E01 are supported. Looking at the following figure, we can see that our image contains two partitions and an unpartitioned ...

With Safari, you learn the way you learn best. Get unlimited access to videos, live online training, learning paths, books, interactive tutorials, and more.

Start Free Trial

No credit card required