Collecting User Information
Last login
Last login failed
Logon count (if count is showing 0, then a MS portal account is being used)
Password policy
Account creation time
Location: SAM\Domains\Account\Users
HIVE Location: C:\Windows\System32\Config\SAM
System Configuration
Current Control Set: SYSTEM\Select
Identify OS version: SOFTWARE\Microsoft\Windows NT\Current Version
NTFS Last Access Time: SYSTEM*CurrentControlSet*Control\FileSystem
-if this is disabled, we can’t see when a file was last accessed
Computer Name: SYSTEM*CurrentControlSet*Control\ComputerName\ComputerName
Time Zone: SYSTEM*CurrentControlSet*Control\TimeZone
Network Interfaces: SYSTEM*CurrentControlSet*Services\TCPIP\Parameters\Interfaces
Network Types: SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\Signatures
System Autostart Programs: SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce AND SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run
Shares of the System: SYSTEM*CurrentControlSet*Services\lanmanserver\Shares\
Last Shutdown Time: SYSTEM*CurrentControlSet*\Control\Windows
HIVE Location: C:\Windows\System32\Config\SYSTEM
User and Program Execution
Search History: NTUSER.dat\Software\Microsoft\Windows*CurrentVersion*Explorer\WordWheelQuery
Typed Paths: NTUSER.dat\Software\Microsoft\Windows*CurrentVersion*Explorer\TypedPaths
RecentDocs: NTUSER.dat\Software\Microsoft\Windows*CurrentVersion*Explorer\RecentDocs
MS Office Files: NTUSER.dat\Software\Microsoft\Office\VERSION\User MRU\Live ID_#\File MRU
HIVE Location: C:\Users<username>\NTUSER.dat