{"podcast":{"title":"CyberCode Academy","slug":"cybercode-academy-7578615","podcast_index_feed_id":7578615,"rss_url":"https://www.spreaker.com/show/6790974/episodes/feed","website_url":"https://www.spreaker.com/podcast/cybercode-academy--6790974","image_url":"https://d3wo5wojvuv7l.cloudfront.net/t_rss_itunes_square_1400/images.spreaker.com/original/5f51ccc7b22fdba95149ffa6346f1533.jpg","author":"CyberCode Academy","episode_count":297,"summary":"Welcome to CyberCode Academy — your audio classroom for Programming and Cybersecurity. 🎧 Each course is divided into a series of short, focused episodes that take you from beginner to advanced level — one lesson at a time. From Python and web development to ethical hacking and digital defense, our content transforms complex concepts into simple, engaging audio learning. Study anywhere, anytime — and level up your skills with CyberCode Academy. 🚀 Learn. Code. Secure. You can listen and download our episodes for free on more than 10 different platforms: https://linktr.ee/cybercode_academy","last_synced_at":"2026-07-13T14:17:20.596630+00:00","page_url":"https://stenobird.com/podcast/cybercode-academy-7578615"},"episode":{"title":"Course 36 - Windows Forensics and Tools | Episode 6: From System Hives to Forensic Analysis","slug":"course-36-windows-forensics-and-tools-episode-6-from-system-hives-to-forensic-analysis","published_at":"2026-06-04T06:00:02+00:00","page_url":"https://stenobird.com/podcast/cybercode-academy-7578615/course-36-windows-forensics-and-tools-episode-6-from-system-hives-to-forensic-analysis","show_page_url":"https://stenobird.com/podcast/cybercode-academy-7578615","url":"https://www.spreaker.com/episode/course-36-windows-forensics-and-tools-episode-6-from-system-hives-to-forensic-analysis--72013648","audio_url":"https://dts.podtrac.com/redirect.mp3/api.spreaker.com/download/episode/72013648/bypassing_windows_to_extract_registry_hives.mp3","summary":"In this lesson, you’ll learn about: Windows Registry structure and forensic analysis1. What is the Windows Registry? A centralized configuration database in Windows Stores system, user, and application settings 🔹 Core Idea Think of it as the brain of Windows configuration 2. Registry StructureThe registry is organized in a strict hierarchy:🔹 Components Hives Keys Subkeys Values 🔹 Analogy Hive → main database file Key → folder Value → actual data entry 3. Main Root Keys🔹 Key Windows Registry Roots HKEY_LOCAL_MACHINE (HKLM) HKEY_CURRENT_USER (HKCU) 🔹 What they represent HKLM → system-wide settings HKCU → settings for the logged-in user 4. Physical Storage of Registry Hives Stored on disk in: C:\\Windows\\System32\\config 🔹 Why this matters Investigators can extract registry data directly from disk Even if Windows is not bootable 5. Core HKLM Sub-Hives🔹 SAM (Security Accounts Manager) Stores: User accounts Password hashes 🔹 SECURITY Hive Stores: Local security policy LSA secrets Authentication data 🔹 SOFTWARE Hive Stores: Installed applications Configuration settings 🔹 SYSTEM Hive Stores: Drivers Services Boot configuration 👉 Key Insight: These hives are critical for system and user reconstruction 6. Modern Windows Registry Extensions🔹 Newer Hives BCD (Boot Configuration Data) Controls boot process ELAM (Early Launch Anti-Malware) Protects early boot stage Browser-related application data hives 👉 Purpose: Improve security and system initialization 7. Forensic Extraction Tools🔹 Common Tools FTK Imager Used to extract registry hives from disk Registry viewers (offline analysis tools) 🔹 Why FTK Imager matters Bypasses OS restrictions Works on live or dead systems 8. Registry Analysis Workflow🔹 Step-by-step process Acquire disk image Extract registry hives Load into analysis too…","meta_description":"In this lesson, you’ll learn about: Windows Registry structure and forensic analysis1. What is the Windows Registry? A centralized configuration database…","key_points":[],"chapters":[],"topics":[],"duration_seconds":1235,"processing_state":"not_requested","actions":[{"name":"request_transcript","method":"POST","url":"https://stenobird.com/v1/public/podcasts/cybercode-academy-7578615/episodes/course-36-windows-forensics-and-tools-episode-6-from-system-hives-to-forensic-analysis/transcription-requests","description":"Idempotently request low-priority transcript generation for this episode."},{"name":"read_markdown","method":"GET","url":"https://stenobird.com/podcast/cybercode-academy-7578615/course-36-windows-forensics-and-tools-episode-6-from-system-hives-to-forensic-analysis.md","description":"Read the agent-friendly Markdown representation of this episode resource."}]}}