hh.sePublications
Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
A Novel Approach to Automating Artifact Extraction and Reporting from Windows Registry: Tool Development and Implementation
Halmstad University, School of Information Technology.
2023 (English)Independent thesis Advanced level (degree of Master (One Year)), 10 credits / 15 HE creditsStudent thesis
Abstract [en]

This thesis suggests a novel program concept for registry forensicpurposes. The concept includes the extraction, processing and reporting of data from the Windows registry in the context of a forensicinvestigation. To develop the concept, comparable tools and paperswere identified and consequentially analysed. The insights gainedwere used to develop a novel approach in the form of a computerprogram.Therefore, the software combines known favourable characteristicsfrom the analysed material with newly developed concepts. Particular attention was paid to the extensive automatisation of the processes and the conception of highly capable reporting functionalities.Afterwards, the suggested program was tested using multiple testing methods to ensure the correctness of the provided functionalities.Furthermore, the program was measured and compared to set it incontext to other similar tools. As a result, this paper can propose aunique solution for acquiring, processing and analysing potential evidence in the Windows registry.

Place, publisher, year, edition, pages
2023. , p. 64
Keywords [en]
Registry, Forensics, Tool
National Category
Computer Sciences
Identifiers
URN: urn:nbn:se:hh:diva-50877OAI: oai:DiVA.org:hh-50877DiVA, id: diva2:1771574
Educational program
Master's Programme in Network Forensics, 60 credits
Supervisors
Examiners
Available from: 2023-06-06 Created: 2023-06-20 Last updated: 2023-06-27Bibliographically approved

Open Access in DiVA

No full text in DiVA

By organisation
School of Information Technology
Computer Sciences

Search outside of DiVA

GoogleGoogle Scholar

urn-nbn

Altmetric score

urn-nbn
Total: 103 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf