Skip to main content

RegRippy is a framework for reading and extracting useful forensics data from Windows registry hives. It is an alternative to RegRipper developed in modern Python 3. It makes use of William Ballenthin's python-registry to access the raw registry hives.

The goal of this project is to provide a framework for quickly and easily developing your own plugins in an incident response scenario.

By default, the script will look for the various hives by reading the REG_SYSTEM, REG_SOFTWARE, REG_SAM, REG_NTUSER and REG_USRCLASS environment variables. This allows the analyst to simply export these in their current shell session and not have to worry about specifying them every time they invoke the script. Alternatively, you can use the --root switch to specify the path to the root of the C: drive. RegRippy will automatically look into the right places depending on which hive each plugin needs.

All plugins should also support both a human-readable and machine-readable output (the Bodyfile format), allowing easy piping to mactime or other tools.

Metadata

Release files for regrippy 2.0.2

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for regrippy 2.0.2
File Size Uploaded
regrippy-2.0.2.tar.gz 50.3 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for regrippy 2.0.2
File Interpreter ABI Platform
regrippy-2.0.2-py3-none-any.whl Python 3 none any Details

Total release size: 103.3 kB

Release files / regrippy-2.0.2.tar.gz

Download URL regrippy-2.0.2.tar.gz
Size 50.3 kB
Tags Source
SHA-256 checksum
How to use checksums
e375a1e62404d62843f1a1b10e69b028390f78c7f248fd26764d1786b55e7f27
BLAKE2b-256 checksum
How to use checksums
208bcdbe6b527dab806f59f396d32a8f372f38efd966cb15d07840455c79f2a6
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.1.0 CPython/3.12.8

Release files / regrippy-2.0.2-py3-none-any.whl

Download URL regrippy-2.0.2-py3-none-any.whl
Size 52.9 kB
Tags Python 3
SHA-256 checksum
How to use checksums
b78469de06b2293b10bff952d22b76999a9ccb61d4eddfb1588b625629d33ca0
BLAKE2b-256 checksum
How to use checksums
a7081a68f12ac809c22dfbcefda7419f625f9ea42211bdbfd8a77a83fb847a0d
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.1.0 CPython/3.12.8

Release history Release notifications | RSS feed

This release

2.0.2 This release

2 release files

2.0.0

2 release files

1.0.1

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page