Skip to main content

reg2es

MIT License PyPI Version

reg2es logo

A command-line tool and Python library for extracting forensic artifacts from Windows NT Registry (REGF) hives and importing them into Elasticsearch.

Includes Registry artifact plugins based on regrippy and inspired by RegRipper.

Usage

reg2es can be used as a standalone command-line tool or integrated directly into your Python scripts.

reg2es SYSTEM SOFTWARE SAM
reg2json NTUSER.DAT -o artifacts.json
from reg2es import reg2es

reg2es(["SYSTEM", "SOFTWARE", "SAM"])

Arguments

Multiple inputs passed in one invocation form one registry dataset. This lets plugins such as localgroups enrich SAM results using SOFTWARE data, regardless of the order of input paths.

reg2es SAM SOFTWARE

reg2es can recursively process all registry files under a specified directory:

tree .
regfiles/
  ├── NTUSER.DAT
  ├── NTUSER.MAN
  ├── SAM
  └── subdirectory/
    ├── SOFTWARE
    └── subsubdirectory/
      ├── SYSTEM
      └── UsrClass.dat

reg2es /regfiles/ # Recursively collects hives as one dataset.

Directory scans process REGF hive files only. Registry transaction logs and unrelated files are not treated as standalone hives.

Common options

  • --plugin NAME: run one plugin; repeat to select several. By default, compatible, default-enabled plugins run. The exhaustive regtime plugin is opt-in.
  • --list-plugins: print the 41 bundled plugins and exit.
  • --size N: set the generation and indexing chunk size (default: 500).
  • --tags tag1,tag2: add custom tags to every document.
  • --quiet: suppress progress output.

reg2es also accepts Elasticsearch connection options including --host, --port, --index, --scheme, --pipeline, --login, --pwd, --ca-certs, and --no-verify-certs. TLS verification is enabled by default; use --ca-certs /path/to/ca.pem for a private CA bundle. Run reg2es --help or reg2json --help for all options.

Examples

When using from the command line:

reg2es SYSTEM --plugin services --host localhost --index registry-artifacts

When using from a Python script:

reg2es(
    ["SYSTEM", "SOFTWARE"],
    host="localhost",
    index="registry-artifacts",
    plugin_names=["services", "systeminfo"],
    additional_tags=["host-01", "case-42"],
)

With Elasticsearch authentication:

reg2es SYSTEM --login elastic --pwd '******'

Appendix

reg2json

reg2es also includes reg2json, a command-line tool for converting Windows NT Registry into JSON files. 🍣 🍣 🍣

reg2json NTUSER.DAT --plugin userassist -o artifacts.json

Use --format jsonl (or ndjson) to write one record per line. The default output extension is .jsonl:

reg2json NTUSER.DAT --plugin userassist --format jsonl -o artifacts.jsonl

Use --split to write one file per plugin. With --split, -o names the output directory:

reg2json collected-hives/ --split -o artifacts/

The exhaustive regtime timeline is excluded from the default plugin set because it emits one record for every registry key. Run it explicitly when needed:

reg2json collected-hives/ --plugin regtime -o regtime.json

You can also convert registry files directly into a Python list[dict]:

from reg2es import reg2json

result: list[dict] = reg2json(
    ["SOFTWARE", "SAM"],
    plugin_names=["localgroups"],
    additional_tags=["host-01"],
)

Output Format Example

{
  "@timestamp": "2015-10-30T07:24:57.814133Z",
  "event": {
    "provider": "registry",
    "module": "windows",
    "dataset": "windows.registry",
    "kind": "event",
    "category": ["registry"],
    "type": ["info"],
    "action": "compname"
  },
  "registry": {
    "hive": "HKLM",
    "key": "SYSTEM\\ControlSet001\\Control\\ComputerName\\ComputerName",
    "path": "HKLM\\SYSTEM\\ControlSet001\\Control\\ComputerName\\ComputerName\\ComputerName",
    "value": "ComputerName",
    "data": {
      "type": "REG_SZ",
      "strings": ["DESKTOP-EXAMPLE"]
    }
  },
  "log": {
    "file": {"path": "/evidence/SYSTEM"}
  },
  "tags": ["registry", "host-01"],
  "reg2es": {
    "plugin": {"name": "compname"},
    "source": {
      "hive": "SYSTEM",
      "key_path": "ROOT\\ControlSet001\\Control\\ComputerName\\ComputerName"
    },
    "value_data": "DESKTOP-EXAMPLE",
    "value_type": "RegSZ"
  }
}

Installation

From PyPI

$ pip install reg2es

With uv

$ uv add reg2es

From GitHub Releases

Standalone binaries are available from GitHub Releases for systems without a Python environment.

$ chmod +x ./reg2es
$ ./reg2es {{options...}}
> reg2es.exe {{options...}}

Contributing

The source code for reg2es is hosted on GitHub: https://github.com/sumeshi/reg2es. Please report issues and feature requests. 🍣 🍣 🍣

License

Standalone release ZIPs include LICENSES.txt with the project, bundled plugin, runtime dependency and build Python license notices. Keep it with the executables when redistributing them.

reg2es is released under the MIT License.

Third-Party Notices

This product includes code derived from regrippy v2.0.3 by Airbus CERT, licensed under Apache License 2.0. The included ShimCache parser carries the original copyright notice of Andrew Davis, Mandiant (2012). See the Apache 2.0 license text and the source-file notices.

Metadata

Release files for reg2es 2.3.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for reg2es 2.3.0
File Size Uploaded
reg2es-2.3.0.tar.gz 114.5 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for reg2es 2.3.0
File Interpreter ABI Platform
reg2es-2.3.0-py3-none-any.whl Python 3 none any Details

Total release size: 197.2 kB

Release files / reg2es-2.3.0.tar.gz

Download URL reg2es-2.3.0.tar.gz
Size 114.5 kB
Tags Source
SHA-256 checksum
How to use checksums
ca548787482d0f948d0ac773bd89fb65178d867619f3636bb7bba914556ebf65
BLAKE2b-256 checksum
How to use checksums
96600030a95d4eda805429eefcb8c7eb8badb7a9b2017f119a82e29d41f13f1f
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via uv/0.12.22 {"installer":{"name":"uv","version":"0.12.22","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

Release files / reg2es-2.3.0-py3-none-any.whl

Download URL reg2es-2.3.0-py3-none-any.whl
Size 82.7 kB
Tags Python 3
SHA-256 checksum
How to use checksums
c431810071e66c6d10a8ccc05671e8bfdfa492af2242dbfcf655c2a7fc836857
BLAKE2b-256 checksum
How to use checksums
c6de4d5ec23add987e4a00bf5ebd7e7d99085417a4b81035c604bb0fff745fca
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via uv/0.12.22 {"installer":{"name":"uv","version":"0.12.22","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

Release history Release notifications | RSS feed

This release

2.3.0 This release

2 release files

2.2.2

2 release files

2.2.1

2 release files

2.2.0

2 release files

2.1.1

2 release files

2.1.0

2 release files

2.0.0

2 release files

1.0.1

2 release files

1.0.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page