analyzing-windows-registry-for-artifacts
mukul975/Anthropic-Cybersecurity-Skills
This comprehensive forensic workflow guides investigators through the extraction and detailed analysis of Windows Registry hives (SAM, SYSTEM, SOFTWARE, etc.). It is used during incident response to uncover critical artifacts, including user activity history, malware persistence mechanisms (autorun keys), installed software records, and evidence of system compromise.