Where can I check for Regestry files in autopsy?

If a mischief administrator has turned off a server using putty (SSH) and post which he/she deleted the putty. Forensics needs to be performed for the same admin system image.
How come an investigator will come to know about putty.
Its ok if investigator came to know via deleted files.
Now How he can make sure that Putty was ran against that server and post which which all activities have been performed using putty.

NOTE: Putty was not installed and it was run portably.

If it was Linux, I would check bash history first. Is there such a thing as cmd or powershell history on Win? If an app was run portably there is a chance that a shellbag was generated. Check UsrClass.dat with Zimmermans Shellbag explorer.

Hey,

Thanks buddy for the help will definitly check it out and revert you with POCs.

Regards,
Abhishek Sharma,
Mob: +91-9458406845
abhigyan17@gmail.com