CHFI (312-49) Digital Forensics Simulation

Master Windows Registry forensics. You will learn to identify specific user execution artifacts and differentiate between systemic and user-based forensic evidence.

Investigation Scenario

You are assigned to investigate a suspected insider threat at a financial institution. Network logs indicate an unauthorized connection was established to an external IP, suspected to be initiated via a portable, unauthorized application. The suspect's workstation has been secured. Your objective is to determine exactly which programs the user interactively launched on the system prior to the incident.

Evidence Collected

[+] System: Windows 10 Pro (Build 19044)
[+] Image: SUSPECT-WKSTN.E01 (SHA256 Verified)
[+] Extracted Hive: C:\Users\suspect\NTUSER.DAT
[+] Extracted Hive: C:\Windows\System32\config\SOFTWARE
[+] Extracted Hive: C:\Windows\System32\config\SYSTEM
[+] Alert Timestamp: 2026-04-10 08:15:22 UTC

Question

In a digital-forensics investigation involving a suspected insider threat, an analyst is examining the suspect's Windows Registry for evidence of recently executed programs. Which Registry key should the analyst prioritize?
Forensic Hint: You need to track GUI-based program executions linked to a specific user. Look for a key located in the user's specific hive (HKCU) that is known to store execution counts and timestamps (often encoded in ROT13).

Expert Analysis

1. What the Evidence Shows

The investigation requires proving that a specific user interactively executed a program. The forensic artifacts collected include both system-wide hives (SOFTWARE, SYSTEM) and user-specific hives (NTUSER.DAT).

2. Forensic Stage

Examination & Analysis: Parsing collected registry hives to reconstruct a timeline of user activity and correlate it with the network alert.

3. Why Correct Answer is Correct (A)

The UserAssist key (located within NTUSER.DAT) tracks GUI-based applications launched by a specific user via Windows Explorer. It provides critical forensic artifacts: the name of the executable, the number of times it was executed (Run Count), and the timestamp of the last execution (FILETIME format). The subkeys are typically ROT13 encoded, requiring simple decryption during analysis.

4. Why Others are Wrong

  • B (USBSTOR): Tracks historical connections of USB mass storage devices to the system, not program executions.
  • C (Winlogon): Manages interactive user logons and logoffs. It does not track which individual programs a user ran.
  • D (Run): This key establishes persistence. Programs listed here automatically start when the user logs in. It does not provide a historical record of manually executed programs.

5. Real-World Forensic Action

An investigator would extract NTUSER.DAT from the forensic image, load it into an analysis tool like RegRipper or Eric Zimmerman’s Registry Explorer. They would then decode the ROT13 UserAssist keys, translate the 64-bit Windows FILETIME timestamps to UTC, and correlate the execution time of suspicious executables with the network alert timestamp.

6. MINI LESSON: Windows Execution Artifacts

  • UserAssist (HKCU): GUI executions, specific to a user profile.
  • Prefetch (*.pf): Located in C:\Windows\Prefetch. System-wide execution artifact used to speed up application load times. Proves execution, run count, and recent run times.
  • Shimcache / AppCompatCache (HKLM): Tracks executables for application compatibility. Good for proving a file existed on the system, even if deleted.
  • Amcache (Amcache.hve): Stores application execution paths and SHA1 hashes.
Explore more CHFI simulations