Is there a way to get OSForensics to give me "User Activity" with only event logs, registry keys and ntuser.dat, instead of using an image?
Announcement
Collapse
No announcement yet.
User Activity
Collapse
X
-
The built in Event log viewer collects similar information. Example below.
For registry files:
By default OSForensics will search for known Windows directories to scan for registry files, however if you have some standalone registry files you can place them in the root directory of a drive (eg a USB thumb drive G: and select this drive to be scanned. OSForensics will scan the following registry files for recent activity:
•SOFTWARE
•SYSTEM
•NTUSER.dat
The user activity module uses many more files than these however. So you won't get all the same data as user activity does unless you have the full disk image.
Comment