The Windows Registry is one of the richest sources of digital evidence. You can find lots of extremely useful pieces of information during the examination of the Registry hives and keys. Computer configurations recently visited webpages and opened documents, connected USB devices, and many other artifacts can all be acquired through Windows Registry forensic examination. -
View it on GitHub