Working with the Registry module
The
Registry
module, developed by Willi Ballenthin, can be used to obtain keys and values from registry hives. Python provides a built-in registry module named _winreg
; however, this module only works on Windows machines. The _winreg
module interacts with the registry on the system running the module. It does not support opening external registry hives.
The Registry
module allows us to interact with supplied registry hives and can be run on non-Windows machines. The Registry
module can be downloaded from https://github.com/williballenthin/python-registry. Click on the releases section to see a list of all stable versions and download version 1.1.0. For this chapter, we use version 1.1.0. Once the archived file ...
Get Learning Python for Forensics now with the O’Reilly learning platform.
O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.