Course 36 - Windows Forensics and Tools | Episode 6: From System Hives to Forensic Analysis

Course 36 - Windows Forensics and Tools | Episode 6: From System Hives to Forensic Analysis

June 4, 2026 · 21 min

About this episode

This episode covers the structure and forensic analysis of the Windows Registry, including its components and extraction tools.

In this lesson, you’ll learn about: Windows Registry structure and forensic analysis1. What is the Windows Registry? A centralized configuration database in Windows Stores system, user, and application settings 🔹 Core Idea Think of it as the brain of Windows configuration 2. Registry StructureThe registry is organized in a strict hierarchy:🔹 Components Hives Keys Subkeys Values 🔹 Analogy Hive → main database file Key → folder Value → actual data entry 3. Main Root Keys🔹 Key Windows Registry Roots HKEY_LOCAL_MACHINE (HKLM) HKEY_CURRENT_USER (HKCU) 🔹 What they represent HKLM → system-wide settings HKCU → settings for the logged-in user 4. Physical Storage of Registry Hives Stored on disk in: C:\Windows\System32\config 🔹 Why this matters Investigators can extract registry data directly from disk Even if Windows is not bootable 5. Core HKLM Sub-Hives🔹 SAM (Security Accounts Manager) Stores: User accounts Password hashes 🔹 SECURITY Hive Stores: Local security policy LSA secrets Authentication data 🔹 SOFTWARE Hive Stores: Installed applications Configuration settings 🔹 SYSTEM Hive Stores: Drivers Services Boot configuration 👉 Key Insight: These hives are critical for system…

More episodes of CyberCode Academy

Explore listener stats, chart rankings, contacts and more on the CyberCode Academy podcast page.