We use cookies to ensure you get the best user experience. For more information see our cookie policy.
To access material, start machines and answer questions login.
In Windows Forensics 1, we learned about where we can find the registry hives and the different artefacts present in these hives. In this room, we will build on that information and learn more about data acquisition and analysis, as during an incident. Therefore, we will not discuss the different artefacts, the information on those artefacts, and where to find them. Instead, we will focus on leveraging the knowledge of these artefacts to perform incident analysis.
In this room, we will learn:
Before continuing, it is highly recommended that you complete the Level 1 and Level 2 paths, especially the following rooms:
Before moving forward, start the lab by clicking the
Start Lab Machine button. It will take 3-5 minutes to load properly. The VM will be accessible on the right side of the split screen. If the VM is not visible, use the blue Show Split View button at the top of the page. Additionally, we will provide you with credentials that you may use if you prefer to connect from your own connected machine.
| Username | administrator |
| Password | thm_4n6 |
| IP | MACHINE_IP |
Anna, the lead at Deer Inc., is investigating suspicious activity on one of the systems. She had been tipped off due to a new user creation activity on the machine. For further analysis, she decided to pull the registry data from the system to answer some questions and identify the scope of the incident. Let's help Anna verify the following information by analysing the attached :
The Expediting Registry Analysis room is only available for Premium or Max subscribers. Signup now to access more than 500 free rooms and learn cyber security through a fun, interactive learning environment.
Already have an account? Log in