Disk Analysis Introduction


Windows Registry Analysis



System Information









Parsing registry hives in bulk with RegRipper







Last updated





















Last updated
rip.exe -r c:\Cases\Analysis\Registry\SOFTWARE -p winverrip.exe -r C:\Cases\Analysis\Registry\SYSTEM -p timezonerip.exe -r C:\Cases\Analysis\Registry\SYSTEM -p nic2rip.exe -r C:\Cases\Analysis\Registry\SOFTWARE -p networklistrip.exe -r C:\Cases\Analysis\Registry\SYSTEM -p shutdownrip.exe -r C:\Cases\Analysis\Registry\SOFTWARE -p defenderattrib *attrib -h NTUSER.DAT
attrib -h UsrClass.datfor /r %i in (*) do (c:\Tools\RegRipper3.0-master\rip.exe -r %i -a > %i.txt)