Forensic examination in the registry has long been referred to the analysis of only readily available Registries from Microsoft Windows®, often one at a time, in vain takes a lot of time and an archaic way. Registry Recon is not just another Registry parser. Digital forensics experts armed with Hibernation Recon are now able to leverage not only the active contents of Windows hibernation files, but also massive volumes of information in the multiple types (and levels) of slack space that often exist within them.
Sylve JT, Marziale V, Richard III GG published the article “Modern Windows Hibernation File Analysis”. It is good work and we recommend to read the article. They provide info about new format of HIBERFIL.SYS that is used in Windows 8, 8.1, and 10.