On Fri, Apr 29, 2011 at 03:15:03PM -0400, Elizabeth Schweinsberg wrote:
It worked! I'm ready to rock and roll with hivex for python now!
Thanks for testing it.
This is going to mean big things for the digital forensics community
-- up until now our only options have been C or Perl for parsing
registry hives, but a lot of the other tools are written in Python.
This will streamline our code base.
If there are any things missing, then bring them up for discussion.
At the moment I'm also interested in the Windows event logs, although
for Win >= Vista there is at least a reasonably good set of GPL tools
for it (
http://computer.forensikblog.de/files/evtx/).
Rich.
--
Richard Jones, Virtualization Group, Red Hat
http://people.redhat.com/~rjones
virt-p2v converts physical machines to virtual machines. Boot with a
live CD or over the network (PXE) and turn machines into Xen guests.
http://et.redhat.com/~rjones/virt-p2v