Conference
Audience
Focus
Call for Papers
Author Instructions
Committee
Keynote
Speakers / Schedule
Venue / Hotel
Registration
Affiliates / Sponsors
Links
Contacts
Proceedings 2009
Proceedings 2008
Proceedings 2007
Proceedings 2006

 

   

Analysis of the ‘Db’ Windows Registry Data Structure

 

Damir Kahvedžić
Centre for Cyber Crime Investigation,
University College Dublin, Ireland,
Tel: +353 1 716 2485
Email: damir.kahvedzic@ucd.ie

Tahar Kechadi
Centre for Cyber Crime Investigation,
University College Dublin, Ireland,
Tel: +353 1 716 2478
Email: tahar.kechadi@ucd.ie
 

ABSTRACT

 

The Windows Registry stores a wide variety of data representing a host of different user properties, settings and program information. The data structures used by the registry are designed to be adaptable to store these differences in a simple format. In this paper we will highlight the existence of a rare data structure that is used to store a large amount of data within the registry hives. We analyse the manner in which this data structure stores its data and the implications that it may have on evidence retrieval and digital investigation. In particular, we reveal that the three of the most popular digital investigation suites fail to recognise this structure and do not allow the investigator to view the contents of the structure.


Keywords: Windows Registry, Data Structure
 

 

 
 
   

Copyright © 2010 Association of Digital Forensics, Security and Law (ADFSL)