hivex Logo

hivex

0
Free
Visit Website

Hivex is a Windows Registry hive extraction library that allows users to read and write Windows Registry 'hive' binary files. It provides a C API and can export the hive as XML. The library is written in C and has bindings for OCaml, Perl, Python, and Ruby. It is licensed under LGPL v2.1. Hivex is a self-contained library that does not use the textual .REG format for output. Instead, it provides a C API and a separate program to export the hive as XML. The library is derived from several sources, including NTREG registry reader/writer library and dumphive, a BSD-licensed Pascal program. Hivex is designed to be more careful about handling error cases, corrupt and malicious registry files, and endianness compared to other libraries.

FEATURES

ALTERNATIVES

Forensic imaging program with full hash authentication and various acquisition options.

A Python tool for in-depth PDF analysis and modification.

Truehunter is a tool designed to detect encrypted containers with a focus on Truecrypt and Veracrypt, utilizing a fast and memory efficient approach.

Browse and analyze iPhone/iPad backups with detailed file properties and various viewers.

Web interface for the Volatility Memory Forensics Framework

Orochi is a collaborative forensic memory dump analysis framework.

A digital artifact extraction framework for extracting data from volatile memory (RAM) samples, providing visibility into the runtime state of a system.

Anti-forensics tool for Red Teamers to erase footprints and test incident response capabilities.

PINNED