Software\Microsoft\Windows NT\CurrentVersion
: Windows version, Service Pack, Installation time and the registered ownerSystem\ControlSet001\Control\ComputerName\ComputerName
: HostnameSystem\ControlSet001\Control\TimeZoneInformation
: TimeZoneSystem\ControlSet001\Control\Filesystem
: Last time access (by default it's disabled with NtfsDisableLastAccessUpdate=1
, if 0
, then, it's enabled).fsutil behavior set disablelastaccess 0
System\ControlSet001\Control\Windows
: Shutdown timeSystem\ControlSet001\Control\Watchdog\Display
: Shutdown count (only XP)System\ControlSet001\Services\Tcpip\Parameters\Interfaces{GUID_INTERFACE}
: Network interfacesSoftware\Microsoft\Windows NT\CurrentVersion\NetworkList\Signatures\Unmanaged
& Software\Microsoft\Windows NT\CurrentVersion\NetworkList\Signatures\Managed
& Software\Microsoft\Windows NT\CurrentVersion\NetworkList\Nla\Cache
: First and last time a network connection was performed and connections through VPNSoftware\Microsoft\WZCSVC\Parameters\Interfaces{GUID}
(for XP) & Software\Microsoft\Windows NT\CurrentVersion\NetworkList\Profiles
: Network type (0x47-wireless, 0x06-cable, 0x17-3G) an category (0-Public, 1-Private/Home, 2-Domain/Work) and last connectionsSystem\ControlSet001\Services\lanmanserver\Shares\
: Share folders and their configurations. If Client Side Caching (CSCFLAGS) is enabled, then, a copy of the shared files will be saved in the clients and server in C:\Windows\CSC
NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Run
NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\RunOnce
Software\Microsoft\Windows\CurrentVersion\Runonce
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
Software\Microsoft\Windows\CurrentVersion\Run
NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Explorer\WordwheelQuery
: What the user searched for using explorer/helper. The item with MRU=0
is the last one.NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Explorer\TypedPaths
: Paths types in the explorer (only W10)NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs
: Recent documents opened by the userNTUSER.DAT\Software\Microsoft\Office{Version}{Excel|Word}\FileMRU
:Recent office docs. Versions:NTUSER.DAT\Software\Microsoft\Office{Version}{Excel|Word} UserMRU\LiveID_###\FileMRU
: Recent office docs. Versions:NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedMRU
NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LasVisitedPidlMRU
NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\Op enSaveMRU
(XP)NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\Op enSavePidlMRU
NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU
NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Explorer\Policies\RunMR
NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{GUID}\Count
USRCLASS.DAT\Local Settings\Software\Microsoft\Windows\Shell\Bags
USRCLASS.DAT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
NTUSER.DAT\Software\Microsoft\Windows\Shell\BagMRU
NTUSER.DAT\Software\Microsoft\Windows\Shell\Bags
HKLM\SYSTEM\ControlSet001\Enum\USBSTOR
monitors each USB device that has been connected to the PC.
Within this registry it's possible to find:HKLM\SYSTEM\ControlSet001\Enum\USB
and comparing the values of the sub-keys it's possible to find the VID valueSOFTWARE\Microsoft\Windows Portable Devices\Devices
can be used to obtain the {GUID}
:NTUSER.DAT\Software\Microsoft\Windows\CurrentVersion\Explorer\Mountpoints2
)System\MoutedDevices
it's possible to find out which device was the last one mounted. In the following image check how the last device mounted in E:
is the Thoshiba one (using the tool Registry Explorer).Software\Microsoft\Windows NT\CurrentVersion\EMDMgmt
you can find the volume serial number. Knowing the volume name and the volume serial number you can correlate the information from LNK files that uses that information.System\ControlSet001\Enum\USBSTOR{VEN_PROD_VERSION}{USB serial}\Properties{83da6326-97a6-4088-9453-a1923f573b29}\
you can find the first and last time the device was connected: