Binary Intelligence

...thoughts and news on digital forensics, pentesting, electronic investigations, and the computer underground.

6/01/2010
Posted by Matt C

Turning RegRipper into WindowsRipper

Harlan Carvey has given us a great tool in RegRipper and it’s undeniable that many examiners have found it to be a useful addition to their toolbox. RegRipper has a very specific purpose – parse the Windows registry. With some modification, we can turn RegRipper into WindowsRipper, an extremely powerful Windows triage tool. Using WindowsRipper we can parse much more than just the registry.


| | |Home