Leveraging Reinforcement Learning for an Efficient Automation of Windows Registry Analysis during Cyber Incident Response

Mohamed Chahine Ghanem, Dominik Wojtczak, Hamza Kheddar, Elhadj Benkhelifa, Erivelton Geraldo Nepomuceno, Chaker Abdelaziz Kerrache · 2025

Windows represents the most common platform found in seized computers due to its widespread presence. This disparity has become worse due to the introduction of Microsoft's Windows. Post Cyber Incident analysis of Microsoft Windows machines has become increasingly challenging due to the everevolving nature of digital threats. Traditional digital forensics methods often struggle to keep pace with modern cybercrime activities' volume, sophistication, and complexity, which either target or originate from Windows machines. In response to these challenges, this research introduces WinRegRL, a framework that combines Reinforcement Learning (RL) and Rule-Based Artificial Intelligence (RB-AI) to enhance the efficiency, effectiveness and accuracy of digital investigations in the context of Windows Operating Systems. WinRegRL fully captures key information, elaborates the MDP environment, solves the RL problem and extracts expertise for later use. Implementation and testing of WinRegRL validated the research hypothesis by enabling optimised analysis and correlation of Registry forensics. Results prove that the proposed RL model out-performs all previous approaches including bling automation and human expert performance in terms of time, the number of artefacts explored, and the accuracy of results. Another advantage of the proposed framework is the ease of repetition, especially in this context, more than one machine of the same configuration is under investigation, a context often faced in real DFIR practice.

Read the paper · More papers on PaperTik