Two possible situations arise when forensically examining a system for evidence of an intrusion: performing live incident response and/or conducting a post mortem examination of hard drivesWindows 7 Registry Forensics: Intrusion Related Activities | DFI News.