Recovering deleted Registry artifacts with Registry Explorer
Registry Explorer is another free Windows Registry forensic tool by another famous digital forensic examiner: Eric Zimmerman. One of the extremely useful features of this tool is its capability to recover deleted records. And it's easier than you might imagine.
Getting ready
Go to Eric's GitHub and click on the Registry Explorer download link. In our case, it's called Registry Explorer/RECmd Version 0.8.1.0. As at the time of writing, the most recent version of the tool is 0.8.1.0. Once RegistryExplorer_RECmd.zip is downloaded, unpack it and you are ready to go.
How to do it...
The steps to recover deleted registry artifacts using registry explorer are as follows:
- Start
RegistryExplorer.exe
, go toOptions
and make sure theRecover deleted keys/values option is enabled, as in the following figure:

Figure 6.11. Registry Explorer Recover deleted keys/values option
Now you are ready to choose a hive file for processing. To do this, go to...