Extracting and viewing Windows Registry files with Magnet AXIOM
You have already learnt a bit about how to use Magnet AXIOM in your forensic examinations, especially if you need to extract and analyze data from shadow copies. But this tool has lots of very useful features, so we will use it in a few more recipes. This time you will learn how to use Magnet AXIOM, and especially its Registry Explorer component, for Windows Registry forensics.
Getting ready
If you are following the recipes in this book one by one, you already have Magnet AXIOM - at least a trial version - installed. If not, refer to Chapter 5, Windows Shadow Copies Analysis, for installation instructions. Once you've installed the tool, you are ready to go.
How to do it...
The steps to be followed for Windows Registry analysis using Magnet AXIOM are as follows:
- Let's create a new case. Once it has been created and all the fields are filled in, go to evidence sources. Click the
Load evidence
button, and you will see theS
ELECT AN...