Windows registry analysis is an integral part of generating or gathering evidence against cyber crimes. Every operating system has its own file system and its own registry. The registry is a database of stored configuration information about the users, hardware, and software on a Windows system. Although the registry was designed to configure the system, to do so, it tracks such a plethora of information about the user's activities, the devices connected to system, what software was used and when, etc. All of this can be useful for the forensic investigator in tracking the who, what, where, and when of a forensic investigation. In Case of windows registry, there are root folders. These root folders are referred to as hives. There are five (5) registry hives. 1. HKEY_USERS: contains all the loaded user profiles 2. HKEYCURRENT_USER : profile of the currently logged-on user 3. HKEYCLASSES_ROOT: configuration information on the application used to open files 4. HK...