Download presentation
Presentation is loading. Please wait.
1
RegRipper Harlan Carvey
2
Create a Place for Regripper
Put it in bin. But where ever, you must execute it in the parent directory of “plugins”
3
Get RegRipper http://code.google.com/p/winforensicaanalysis
4
Setup Regripper Unpack the zip file
Move all to the root of the regripper directory Update the plugins form Test drive
5
RegRipper Interface
6
Create a Case Folder
7
Get Your Hive Files C:\Windows\System32\Config - Get ‘em all.
8
Save in your case folder
9
There they are
10
RegRipper Frame work for extracting and displaying specific info from hive files Permits the tailoring of registry reports Enables the writing of plugins The contents of the “plugins” file determines which and in what order the plugins are executed
11
Plugins File
12
RegRipper Interface Which hive file will be analyzed
Where to put the report Which Plugins file to use
13
Example
14
Output
15
Log
16
Command Line exe
Similar presentations
© 2025 SlidePlayer.com. Inc.
All rights reserved.