RegRecon
RegRecon is my solution to triaging computers that come into the lab for a forensic examination.
By exporting out the registry files prior to imaging, I can quickly use RegRecon to get dates and times or usernames to determin if the device is in scope, or is likely to have some sort of evidentiary value.
This is a WORK IN PROGESS
Add you registry hives, Save the regrecon_templates.json in the same location as the .exe if you want preset templates In the registry tree, right click on the key to tag or un tag Click Export Tagged for a txt report on your tagged keys for easier reporting.
To do: right click to convert HEX to ASCII right click to convert HEX to Windows DATETIME