Windows records privacy permissions and recent access to protected
resources through the Capability Access Manager. Within each user's
registry hive, ConsentStore entries can associate resources such as
location, microphone, camera, and media libraries with packaged
applications or traditional desktop executables.
Registry Resource Access artifacts can help establish which applications
were associated with privacy-sensitive Windows capabilities.
Packaged-app records preserve the application identity and its stored
consent state, while non-packaged records may tie an executable path to
the beginning and end of its most recent resource-access interval. This
information can strengthen an application-activity timeline and help
assess whether an executable was configured or observed using a
sensitive capability. The records do not reveal the content accessed
and, by themselves, do not prove that the user initiated the activity.
Registry Resource Access data is stored in the per-user registry hive:
C:\Users\<USERNAME>\NTUSER.DAT
This section will discuss how to use ArtiFast to extract Windows
Registry Resource Access artifacts from Windows device files and what
kind of digital forensics insights can be gained from the artifacts.
After a case has been created and evidence has been added for the
investigation, at the Artifact Selection phase, the Windows Registry
Resource Access artifact parsers can be selected:
Once the ArtiFast parser plugins complete processing the artifacts for analysis, they can be reviewed via Artifact View or Timeline View, with indexing, filtering, and searching capabilities. Below is a detailed description of Windows Registry Resource Access artifacts in ArtiFast.
Registry Resource Access Permission (Packaged Apps)
Registry Resource Access (Non-Packaged Apps)
For more information or suggestions please contact: asli.beyhan@forensafe.com