Forensics — Registry Furensics (Day’s 16)
try hack me
Forensics — Registry Furensics (Day’s 16)
try hack me
author name = Mo Rashid (splo)
hackathon every day lab solve
Youtube ~ khan sploit
my notes is very simple point lab answer
only you problem solve brother |please you seach the you tube channer


Task1 ~ Introduction
Q1 ~ I successfully have access to my target machine!
Ans1~ no needed answer
Task2 ~Investigate the Gifts Delivery Malfunctioning
Q1 ~ What application was installed on the dispatch-srv01 before the abnormal activity started?
Ans1~ DroneManager Updater
Q2 ~ What is the full path where the user launched the application (found in question 1) from?
Ans2~ C:\Users\dispatch.admin\Downloads\DroneManager_Setup.exe
Q3 ~ Which value was added by the application to maintain persistence on startup?
Ans3 ~ “C:\Program Files\DroneManager\dronehelper.exe” — background
Q4 ~ If you enjoyed today’s room, feel free to check out the Expediting Registry Analysis room.
ans4 ~ No needed of answer
메타데이터
- post_id
- e8fdbc04c80e
- slug
- forensics-registry-furensics-days-16-e8fdbc04c80e
- url
- https://medium.com/@rashidsheikh8840/forensics-registry-furensics-days-16-e8fdbc04c80e
- canonical_url
- https://medium.com/@rashidsheikh8840/forensics-registry-furensics-days-16-e8fdbc04c80e
- author_url
- https://medium.com/@rashidsheikh8840
- status
- ok
- fetched_at
- 2026-07-15 11:38:27