Question: Analyze the SYSTEM hive using the Registry Explorer tool and unswer the following questions: a . What is the current control set? ( SYSTEMSelectCurrent )

Analyze the SYSTEM hive using the Registry Explorer tool and unswer the following questions:
a. What is the current control set? (SYSTEMSelectCurrent)
Why is it important to know what the CurrentControlSet is?
b. What is the timezone when the image of the evidence hard disk was captured? (SYSTEMCurrentControlSetYControllTimeZonelnformation)
Why is it important to know the time zone that the machine is set in?
c. Is the LastAccess timestamp disabled?
(SYSTEMCurrentControlSetControl/FileSystem)
Locate NtfsDisableLastAccessUpdate. If set to Ox1, then Access timestamps aro disabled and will not update when a file is opened.
d. What is the computer name?
(SYSTEMYCurrentControlSet Control CompuerNamelComputerName)
e. Check the GUID {5185491C-401D-491E-8c6F-07F6AFFF 1A64}(SYSTEMCurreniControlSet Services/Tcpip YParameters Interfaces)
What is the DHCPDomain?
What is the last DHCPIPAddress?
f. Find the Network named LOT38
(SOFTWARETMicrosoft WindowsiNTVCurrent Version\NetworkList Signatures) Unmmanaged,
SOFTWAREMierrsoft Window NNTCurrent Version (NetworkList Profiles)
\table[[Description],[Gateway],[ProfiloGuid],[First Connection],[Last Connection],[Connection Type],[WIGLE lookup?]]
For the WIGLE lookup, go to wigle net > View > Basic search
g. Find the Network named District Taco
(SOFTWARE(Microsoft\ WindowsNTVCurent Version)NetworkList'SignaturesalUmananaged, SOFTWARELMicrosoft WindowsNICursentVerstonWNetwarkList\Profiles)
\table[[Description,],[Gateway,],[ProfileGuid,],[First Conncction,],[Last Connection,],[Connoction Typo,],[WIGLE lookup?,]]
h. When was the computer gracefully shur down last time (64 bit Hes Vallue-Litule Endina)?(SYSTEMCurrentControlSet)ControWindows)
 Analyze the SYSTEM hive using the Registry Explorer tool and unswer

Step by Step Solution

There are 3 Steps involved in it

1 Expert Approved Answer
Step: 1 Unlock blur-text-image
Question Has Been Solved by an Expert!

Get step-by-step solutions from verified subject matter experts

Step: 2 Unlock
Step: 3 Unlock

Students Have Also Explored These Related Databases Questions!