RegRippy is a framework for reading and extracting useful forensics data from Windows registry hives. It is an alternative to RegRipper developed in modern Python 3. It makes use of William Ballenthin's python-registry to access the raw registry hives.
The goal of this project is to provide a framework for quickly and easily developing your own plugins in an incident response scenario.
By default, the script will look for the various hives by reading the REG_SYSTEM, REG_SOFTWARE, REG_SAM, REG_NTUSER and REG_USRCLASS environment variables. This allows the analyst to simply export these in their current shell session and not have to worry about specifying them every time they invoke the script.
Alternatively, you can use the --root switch to specify the path to the root of the C: drive. RegRippy will automatically look into the right places depending on which hive each plugin needs.
All plugins should also support both a human-readable and machine-readable output (the Bodyfile format), allowing easy piping to mactime or other tools.
Metadata
Release files for regrippy 2.0.2
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| regrippy-2.0.2.tar.gz | 50.3 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| regrippy-2.0.2-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 103.3 kB
Release files / regrippy-2.0.2.tar.gz
| Download URL | regrippy-2.0.2.tar.gz |
|---|---|
| Size | 50.3 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
e375a1e62404d62843f1a1b10e69b028390f78c7f248fd26764d1786b55e7f27
|
|
BLAKE2b-256 checksum How to use checksums |
208bcdbe6b527dab806f59f396d32a8f372f38efd966cb15d07840455c79f2a6
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.1.0 CPython/3.12.8
|
Release files / regrippy-2.0.2-py3-none-any.whl
| Download URL | regrippy-2.0.2-py3-none-any.whl |
|---|---|
| Size | 52.9 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
b78469de06b2293b10bff952d22b76999a9ccb61d4eddfb1588b625629d33ca0
|
|
BLAKE2b-256 checksum How to use checksums |
a7081a68f12ac809c22dfbcefda7419f625f9ea42211bdbfd8a77a83fb847a0d
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.1.0 CPython/3.12.8
|