170 likes | 199 Views
Learn how to setup and use RegRipper for Windows forensic analysis. Get detailed instructions on downloading, unpacking, updating plugins, creating a case folder, and analyzing hive files. Enhance your investigative capabilities with RegRipper's framework for extracting and displaying registry information.
E N D
RegRipper Harlan Carvey
Create a Place for Regripper Put it in bin. But where ever, you must execute it in the parent directory of “plugins”
Setup Regripper • Unpack the zip file • Move all to the root of the regripper directory • Update the plugins form • http://code.google.com/p/regripperplugins/ • Test drive
Get Your Hive Files C:\Windows\System32\Config - Get ‘em all.
RegRipper • Frame work for extracting and displaying specific info from hive files • Permits the tailoring of registry reports • Enables the writing of plugins • The contents of the “plugins” file determines which and in what order the plugins are executed
RegRipper Interface Which hive file will be analyzed Where to put the report Which Plugins file to use