Analyzing Restore Point Registry Settings

We have alluded to it long enough, and it is now time to venture into the registry keys that are stored as part of the restore points. Restore points came out with Windows XP and ME. Although Windows Server 2003 does not come with restore points installed, there is an installation hack that allows you to install them from the XP CD, which is a nice feature to add. Windows Vista and Windows 7 both have the restore points capability enabled by default. The purpose of restore points in general is to take a snapshot of your system so you can restore it to a previous point if things go wrong. One thing you have probably noticed is that no server editions support restore points natively. While restore points ...

Get Mastering Windows Network Forensics and Investigation, 2nd Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.