This chapter provides a detailed discussion of the use of RegRipper, how to get the most out of using RegRipper, and how to extend the tool to meet your own needs.


RegRipper; Rip
Information in this chapter
• What is RegRipper?
• Getting the most out of RegRipper


Since it was first released, RegRipper has been downloaded a great number of times and seems to be used by a great many analysts. However, I tend to wonder just how many analysts really use RegRipper to get the most from the Registry hives they’re examining, as opposed to those that simply run the tool because they heard someone say that they should. There’s much more available to an analyst when employing a tool such as ...

Get Windows Registry Forensics, 2nd Edition now with O’Reilly online learning.

O’Reilly members experience live online training, plus books, videos, and digital content from 200+ publishers.