Visit Website

Hivex is a Windows Registry hive extraction library that allows users to read and write Windows Registry 'hive' binary files. It provides a C API and can export the hive as XML. The library is written in C and has bindings for OCaml, Perl, Python, and Ruby. It is licensed under LGPL v2.1. Hivex is a self-contained library that does not use the textual .REG format for output. Instead, it provides a C API and a separate program to export the hive as XML. The library is derived from several sources, including NTREG registry reader/writer library and dumphive, a BSD-licensed Pascal program. Hivex is designed to be more careful about handling error cases, corrupt and malicious registry files, and endianness compared to other libraries.

FEATURES

ALTERNATIVES

An extensible network forensic analysis framework with deep packet analysis and plugin support.

An anti-forensic kill-switch tool for USB ports to shut down the computer immediately in case of unauthorized access.

PowerForensics is a PowerShell digital forensics framework for hard drive forensic analysis.

Fridump is an open source memory dumping tool using the Frida framework for dumping memory addresses from various platforms.

Toolkit for post-mortem analysis of Docker runtime environments using forensic HDD copies.

Orochi is a collaborative forensic memory dump analysis framework.

Malscan is a tool to scan process memory for YARA matches and execute Python scripts.

A digital artifact extraction framework for extracting data from volatile memory (RAM) samples, providing visibility into the runtime state of a system.

CyberSecTools logoCyberSecTools

Explore the largest curated directory of cybersecurity tools and resources to enhance your security practices. Find the right solution for your domain.

Copyright © 2024 - All rights reserved