hivex Logo

hivex

0
Free
Visit Website

Hivex is a Windows Registry hive extraction library that allows users to read and write Windows Registry 'hive' binary files. It provides a C API and can export the hive as XML. The library is written in C and has bindings for OCaml, Perl, Python, and Ruby. It is licensed under LGPL v2.1. Hivex is a self-contained library that does not use the textual .REG format for output. Instead, it provides a C API and a separate program to export the hive as XML. The library is derived from several sources, including NTREG registry reader/writer library and dumphive, a BSD-licensed Pascal program. Hivex is designed to be more careful about handling error cases, corrupt and malicious registry files, and endianness compared to other libraries.

FEATURES

ALTERNATIVES

A tool for discovering, analyzing, and remedying sensitive data

A library to access the Extensible Storage Engine (ESE) Database File (EDB) format used in various Windows applications.

Comprehensive suite for advanced file analysis and software supply chain security.

libevt is a library to access and parse Windows Event Log (EVT) files.

Dump the contents of the location database files on iOS and macOS with output options like KML and CSV.

A free, open source collection of tools for forensic artifact and image analysis.

wxHexEditor is a free hex editor / disk editor with various data manipulation operations and visualization functionalities.

A cross-platform registry hive editor for forensic analysis with advanced features like hex viewer and reporting engine.

PINNED