Registry forensics has long been relegated to analyzing only readily accessible Windows® Registries, often one at a time, in a needlessly time-consuming and archaic way. Registry Recon is not just another Registry parser. Arsenal developed powerful new methods to parse Registry data so that Registries which have existed on a Windows system over time can be rebuilt, providing unique insight into how Registry data has changed over time. Registry Recon provides access to an enormous volume of Registry data which has been effectively deleted, whether that deletion occurred due to benign system activity, malfeasance by a user, or even re-imaging by IT personnel.
Make no mistake about it - if you use Registry Recon, you have a significant advantage over those that do not.
Viewing multiple Registries from previous Windows installations reconstructed from unallocated space in a high-stakes case
Viewing multiple DateLastConnected values (related to a WiFi network) reconstructed from active Registry and Volume Shadow Copies
Viewing a bam value which exists only in unallocated space
Viewing a crucial Run value in a high-stakes case found only in unallocated space
Viewing a rebuilt Registry from a Stuxnet memory capture
Unlock the potential of huge volumes of Windows Registry data and see how Registries changed over time.
Recently accessed files
Removable storage activity
Usernames and Passwords
Efficient harvesting of Registry data from entire disk images
Resurrection of Registries long since forgotten
Access to enormous amounts of deleted Registry data
Unique keys and values shown by default in historical fashion
Seamless access to all instances of keys and values
Windows restore point and Volume Shadow Copy support
Ability to view keys (and their values) at particular points in time
Automatic decoding of particularly interesting Registry keys
"Registry Recon helps cut through tedious work and recovers valuable information that is not available without burning enormous amounts of time."
Senior Investigator, U.S. Department of Labor
"The sheer volume of Registry data that Registry Recon finds, and the methods used to visualize it, are astounding. We were able to analyze a newly complete Registry from a previous installation of Windows that was over two years old."
Director, Forensic West, DTI
Buy an Arsenal license and choose a subscription length (see the increasing discounts!) that works best for you. Want to try Registry Recon first? No problem. Email sales to start your evaluation.