Announcement

Collapse
No announcement yet.

User Activity

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • User Activity

    Is there a way to get OSForensics to give me "User Activity" with only event logs, registry keys and ntuser.dat, instead of using an image?

  • #2
    The built in Event log viewer collects similar information. Example below.

    Click image for larger version  Name:	image.png Views:	0 Size:	346.2 KB ID:	57557

    For registry files:
    By default OSForensics will search for known Windows directories to scan for registry files, however if you have some standalone registry files you can place them in the root directory of a drive (eg a USB thumb drive G: and select this drive to be scanned. OSForensics will scan the following registry files for recent activity:

    •SOFTWARE
    •SYSTEM
    •NTUSER.dat

    The user activity module uses many more files than these however. So you won't get all the same data as user activity does unless you have the full disk image.

    Comment

    Working...
    X