Which forensic technique can recover deleted registry keys from a Windows system where the keys are no longer present in the live hive?
-
A
Parsing Volume Shadow Copies for earlier versions of the hive file
-
B
Reviewing Windows Event Logs for registry modification events
-
C
Searching browser cache files for previously exported .REG files
-
D
Analyzing prefetch files for registry access patterns