Search icon CANCEL
Subscription
0
Cart icon
Your Cart (0 item)
Close icon
You have no products in your basket yet
Save more on your purchases! discount-offer-chevron-icon
Savings automatically calculated. No voucher code required.
Arrow left icon
All Products
Best Sellers
New Releases
Books
Videos
Audiobooks
Learning Hub
Newsletter Hub
Free Learning
Arrow right icon
timer SALE ENDS IN
0 Days
:
00 Hours
:
00 Minutes
:
00 Seconds
Arrow up icon
GO TO TOP
Windows Forensics Cookbook

You're reading from   Windows Forensics Cookbook Over 60 practical recipes to acquire memory data and analyze systems with the latest Windows forensic tools

Arrow left icon
Product type Paperback
Published in Aug 2017
Publisher
ISBN-13 9781784390495
Length 274 pages
Edition 1st Edition
Concepts
Arrow right icon
Authors (2):
Arrow left icon
 de Courcier de Courcier
Author Profile Icon de Courcier
de Courcier
Oleg Skulkin Oleg Skulkin
Author Profile Icon Oleg Skulkin
Oleg Skulkin
Arrow right icon
View More author details
Toc

Table of Contents (19) Chapters Close

Title Page
Credits
About the Authors
About the Reviewer
www.PacktPub.com
Customer Feedback
Preface
1. Digital Forensics and Evidence Acquisition FREE CHAPTER 2. Windows Memory Acquisition and Analysis 3. Windows Drive Acquisition 4. Windows File System Analysis 5. Windows Shadow Copies Analysis 6. Windows Registry Analysis 7. Main Windows Operating System Artifacts 8. Web Browser Forensics 9. Email and Instant Messaging Forensics 10. Windows 10 Forensics 11. Data Visualization 12. Troubleshooting in Windows Forensic Analysis

Parsing registry files with RegRipper


RegRipper is an open source Windows forensic tool developed by the famous forensicator Harlan Carvey, the author of the Windows Forensic Analysis series. It's written in Perl, and has a lot of useful plugins available. Also, digital forensic examiners capable of writing in Perl can create their own plugins for their specific needs.

Getting ready

Go to RegRipper's page at Harlan's GitHub, click on the green button (Clone or Download), and choose the Download ZIP option. Once the archive is downloaded (in our case it is named RegRipper2.8-master.zip), unpack it, and you are ready to go.

How to do it...

The steps for parsing registry files with RegRipper:

  1. You already know how to export registry files from disk images, at least with Magnet AXIOM. So, we are sure you have a file to parse with RegRipper. Start rr.exe, and you will see a window like the one in the following figure:

Figure 6.9. RegRipper main window

Here, you have three fields to fill in:

    • Hive File...

lock icon The rest of the chapter is locked
Register for a free Packt account to unlock a world of extra content!
A free Packt account unlocks extra newsletters, articles, discounted offers, and much more. Start advancing your knowledge today.
Unlock this book and the full library FREE for 7 days
Get unlimited access to 7000+ expert-authored eBooks and videos courses covering every tech area you can think of
Renews at $15.99/month. Cancel anytime
Visually different images