Skip to content

Feature Request: Windows Registry Transaction Logs #4952

@elad-levi-cyberark

Description

@elad-levi-cyberark

I've observed that Plaso does not process the Registry's transaction logs. As a result, any recent changes made to the registry are not captured by Plaso, potentially omitting crucial information from the researcher's view.

References

https://andreafortuna.org/2021/02/06/windows-registry-transaction-logs-in-forensic-analysis/
https://www.youtube.com/watch?v=3oV_DHmPl1Y

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew or improved functionalityparsersIssues related to parsers and parser plug-ins

    Projects

    Status

    No status

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions