Collecting User Information

Last login

Last login failed

Logon count (if count is showing 0, then a MS portal account is being used)

Password policy

Account creation time

Location: SAM\Domains\Account\Users

HIVE Location: C:\Windows\System32\Config\SAM

System Configuration

Current Control Set: SYSTEM\Select

Identify OS version: SOFTWARE\Microsoft\Windows NT\Current Version

NTFS Last Access Time: SYSTEM*CurrentControlSet*Control\FileSystem

-if this is disabled, we can’t see when a file was last accessed

Computer Name: SYSTEM*CurrentControlSet*Control\ComputerName\ComputerName

Time Zone: SYSTEM*CurrentControlSet*Control\TimeZone

Network Interfaces: SYSTEM*CurrentControlSet*Services\TCPIP\Parameters\Interfaces

Network Types: SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkList\Signatures

System Autostart Programs: SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce AND SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run

Shares of the System: SYSTEM*CurrentControlSet*Services\lanmanserver\Shares\

Last Shutdown Time: SYSTEM*CurrentControlSet*\Control\Windows

HIVE Location: C:\Windows\System32\Config\SYSTEM

User and Program Execution

Search History: NTUSER.dat\Software\Microsoft\Windows*CurrentVersion*Explorer\WordWheelQuery

Typed Paths: NTUSER.dat\Software\Microsoft\Windows*CurrentVersion*Explorer\TypedPaths

RecentDocs: NTUSER.dat\Software\Microsoft\Windows*CurrentVersion*Explorer\RecentDocs

MS Office Files: NTUSER.dat\Software\Microsoft\Office\VERSION\User MRU\Live ID_#\File MRU

HIVE Location: C:\Users<username>\NTUSER.dat