hivex Logo

hivex

0
Free
Visit Website

Hivex is a Windows Registry hive extraction library that allows users to read and write Windows Registry 'hive' binary files. It provides a C API and can export the hive as XML. The library is written in C and has bindings for OCaml, Perl, Python, and Ruby. It is licensed under LGPL v2.1. Hivex is a self-contained library that does not use the textual .REG format for output. Instead, it provides a C API and a separate program to export the hive as XML. The library is derived from several sources, including NTREG registry reader/writer library and dumphive, a BSD-licensed Pascal program. Hivex is designed to be more careful about handling error cases, corrupt and malicious registry files, and endianness compared to other libraries.

FEATURES

ALTERNATIVES

A library to access FileVault Drive Encryption (FVDE) encrypted volumes on Mac OS X systems.

A digital forensic tool for creating forensic images of computer hard drives and analyzing digital evidence.

A library and tools to access and manipulate VMware Virtual Disk (VMDK) files.

A reliable end-to-end DFIR solution for boosting cyber incident response and forensics capacity.

A powerful reverse engineering framework

A network forensics tool for visualizing packet captures as network diagrams with detailed analysis.

Python tool for remotely or locally dumping RAM of a Linux client for digital forensics analysis.

RegRippy is a modern Python 3 alternative to RegRipper for extracting data from Windows registry hives.

CyberSecTools logoCyberSecTools

Explore the largest curated directory of cybersecurity tools and resources to enhance your security practices. Find the right solution for your domain.

Copyright © 2024 - All rights reserved