SEC595: Applied Data Science and AI/Machine Learning for Cybersecurity Professionals


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsWindows keeps track of everything you do on the system, what you have connected tothe computer and what you have used on the system. Knowing where to look for this information and what it tells you is one of the great challenges incident responders and analysts have when looking at computers. This paper documents the registry remnants that remain from both hardware connections (NIC's) being inserted into the computer, as well as information within the registry regarding the networks that the computer has connected too in the past for both Windows XP and Windows Vista systems.


Jonathan Risto is a Principal Instructor at the SANS Institute and Technical Director for the Canadian Cyber Posture Program. Co-author of LDR516: Strategic Vulnerability and Threat Management, he helps leaders turn exposure data into actionable risk programs through frameworks like VMMM and CTEMMM.
Read more about Jonathan Risto














