regipy
Regipy is a python library for parsing offline registry hives!
Features:
Use as a library
Recurse over the registry hive, from root or a given path and get all subkeys and values
Read specific subkeys and values
Apply transaction logs on a registry hive
- Command Line Tools:
Dump an entire registry hive to json
Apply transaction logs on a registry hive
Compare registry hives
Execute plugins from a robust plugin system (i.e: amcache, shimcache, extract computer name…)
- Project page:
Using as a library:
from regipy.registry import RegistryHive
reg = RegistryHive('/Users/martinkorman/Documents/TestEvidence/Registry/Vibranium-NTUSER.DAT')
# Iterate over a registry hive recursively:
for entry in reg.rec_subkeys(as_json=True):
print(entry)
# Iterate over a key and get all subkeys and their modification time:
for sk in reg.get_key('Software').get_subkeys():
print(sk.name, convert_wintime(sk.header.last_modified).isoformat())
# Get values from a specific registry key:
reg.get_key('Software\Microsoft\Internet Explorer\BrowserEmulation').get_values(as_json=True)
# Use plugins:
from regipy.plugins.ntuser.ntuser_persistence import NTUserPersistencePlugin
NTUserPersistencePlugin(reg, as_json=True).run()
# Run all supported plugins on a registry hive:
run_relevant_plugins(reg, as_json=True)
Install
Install regipy and the command line tools dependencies:
pip install regipy[cli]
NOTE: using pip with regipy[cli] instead of the plain regipy is a significant change from version 1.9.x
For using regipy as a library, install only regipy which comes with fewer dependencies:
pip install regipy
Metadata
Release files for regipy2 2.2.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| regipy2-2.2.1.tar.gz | 37.8 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| regipy2-2.2.1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 94.6 kB
Release files / regipy2-2.2.1.tar.gz
| Download URL | regipy2-2.2.1.tar.gz |
|---|---|
| Size | 37.8 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
f2ba248cfc6ad49617b15cb0d84b59c35c4e2a21e521fdc055561a5d59a40f96
|
|
BLAKE2b-256 checksum How to use checksums |
b605982ed1dca9e410c32ce9291acdfa0a6dd2b1a66c78fac15af1f872bac60e
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/3.4.2 importlib_metadata/4.8.1 pkginfo/1.7.1 requests/2.26.0 requests-toolbelt/0.9.1 tqdm/4.62.3 CPython/3.6.10
|
Release files / regipy2-2.2.1-py3-none-any.whl
| Download URL | regipy2-2.2.1-py3-none-any.whl |
|---|---|
| Size | 56.8 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
33ea7ad04b08445abc91ab491ee5373bad9cffe5ff935058c8bf6c71aab65467
|
|
BLAKE2b-256 checksum How to use checksums |
1d655fe668572748376c9518cd55d871b0f4999d830e5dfd2768dc872f0fb5c8
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/3.4.2 importlib_metadata/4.8.1 pkginfo/1.7.1 requests/2.26.0 requests-toolbelt/0.9.1 tqdm/4.62.3 CPython/3.6.10
|