This paper discusses the significance of Windows registry forensics in aiding computer and network investigations, focusing on its structure and the keys with forensic value. It covers the organization of the Windows registry, detailing its root keys and how forensic analysis can retrieve evidence related to intrusion detection. The authors illustrate the applications of forensic keys to uncover evidence of software installations and potential malicious actions by hackers.