Windows-based systems have a central repository of settings called the Windows Registry. The registry is often a valuable source of information that can be used to clarify and corroborate other information of relevance to an investigation recovered from the filesystem. The Windows Registry is a vital part of the Windows operating system and maintains the configuration of the system and supported application programs as well as the users accessing the system and attached devices and networks.
The registry consists of a directory structure containing folders or "hives" that contain files or keys that contain values and, sometimes, sub-keys. Each key contains specific values that are used by the operating system or an application that relies on the value, for instance, the time zone used by the computer, the status of remote access settings, or details of a storage device attached.