CHFI (312-49) Digital Forensics Simulation
Master Windows Registry forensics. You will learn to identify specific user execution artifacts and differentiate between systemic and user-based forensic evidence.
Investigation Scenario
You are assigned to investigate a suspected insider threat at a financial institution. Network logs indicate an unauthorized connection was established to an external IP, suspected to be initiated via a portable, unauthorized application. The suspect's workstation has been secured. Your objective is to determine exactly which programs the user interactively launched on the system prior to the incident.
Evidence Collected
[+] Image: SUSPECT-WKSTN.E01 (SHA256 Verified)
[+] Extracted Hive: C:\Users\suspect\NTUSER.DAT
[+] Extracted Hive: C:\Windows\System32\config\SOFTWARE
[+] Extracted Hive: C:\Windows\System32\config\SYSTEM
[+] Alert Timestamp: 2026-04-10 08:15:22 UTC
Question
Expert Analysis
1. What the Evidence Shows
The investigation requires proving that a specific user interactively executed a program. The forensic artifacts collected include both system-wide hives (SOFTWARE, SYSTEM) and user-specific hives (NTUSER.DAT).
2. Forensic Stage
Examination & Analysis: Parsing collected registry hives to reconstruct a timeline of user activity and correlate it with the network alert.
3. Why Correct Answer is Correct (A)
The UserAssist key (located within NTUSER.DAT) tracks GUI-based applications launched by a specific user via Windows Explorer. It provides critical forensic artifacts: the name of the executable, the number of times it was executed (Run Count), and the timestamp of the last execution (FILETIME format). The subkeys are typically ROT13 encoded, requiring simple decryption during analysis.
4. Why Others are Wrong
- B (USBSTOR): Tracks historical connections of USB mass storage devices to the system, not program executions.
- C (Winlogon): Manages interactive user logons and logoffs. It does not track which individual programs a user ran.
- D (Run): This key establishes persistence. Programs listed here automatically start when the user logs in. It does not provide a historical record of manually executed programs.
5. Real-World Forensic Action
An investigator would extract NTUSER.DAT from the forensic image, load it into an analysis tool like RegRipper or Eric Zimmerman’s Registry Explorer. They would then decode the ROT13 UserAssist keys, translate the 64-bit Windows FILETIME timestamps to UTC, and correlate the execution time of suspicious executables with the network alert timestamp.
6. MINI LESSON: Windows Execution Artifacts
- UserAssist (HKCU): GUI executions, specific to a user profile.
- Prefetch (*.pf): Located in
C:\Windows\Prefetch. System-wide execution artifact used to speed up application load times. Proves execution, run count, and recent run times. - Shimcache / AppCompatCache (HKLM): Tracks executables for application compatibility. Good for proving a file existed on the system, even if deleted.
- Amcache (Amcache.hve): Stores application execution paths and SHA1 hashes.