Talk With an Expert

The Registry Hives You May be MSIX-ING: Registry Redirection with MS MSIX

  • Thu, Nov 9, 2023
  • 1:00PM - 2:00PM UTC
  • English
  • Mari DeGrazia
  • Technical Presentation
Webcast Hero

In Digital Forensics we use the registry hives to help paint the picture of what a threat actor may have done while in the network. These registry hives can tell us things like what documents were opened, what folders were traversed into and what files may have been opened or saved on the computer. Forensics has traditionally focused on a handful of registry hives. With the introduction of MSIX in Windows 10+, per application registry hives were introduced. These hives contain information that may not be located in the traditional hives that examiners have been looking at, and could contain valuable information not located in other places. In this presentation, I will walk through were to find these, what tools to use to work with them and why they may be relevant to your investigations.

Meet the speaker

Mari DeGrazia
Mari DeGrazia

Mari DeGrazia

Mari DeGrazia loves the satisfaction of solving a good puzzle. That fascination paired with her technical abilities has made digital forensics the perfect career fit. She has 20 years of experience in the IT industry, including 10 years in DFIR.

Read more about Mari DeGrazia