• Stars
    star
    157
  • Rank 238,399 (Top 5 %)
  • Language
    Python
  • License
    Apache License 2.0
  • Created about 10 years ago
  • Updated 7 months ago

Reviews

There are no reviews yet. Be the first to send feedback to the community and the maintainers!

Repository Details

Windows Registry Knowledge Base
winreg-kb is a project to build a Windows Registry Knowledge Base.

winregrc is a Python module part of winreg-kb to allow reuse of Windows
Registry Resources.

For more information see:
* Project documentation: https://winreg-kb.readthedocs.io/en/latest

More Repositories

1

libfvde

Library and tools to access FileVault Drive Encryption (FVDE) encrypted volumes
C
336
star
2

libesedb

Library and tools to access the Extensible Storage Engine (ESE) Database File (EDB) format.
C
334
star
3

libfsapfs

Library and tools to access the Apple File System (APFS)
C
329
star
4

libpff

Library and tools to access the Personal Folder File (PFF) and the Offline Folder File (OFF) format
C
283
star
5

libewf

Libewf is a library to access the Expert Witness Compression Format (EWF)
C
255
star
6

libbde

Library and tools to access the BitLocker Drive Encryption (BDE) encrypted volumes
C
214
star
7

libyal

Yet another library library (and tools)
C
200
star
8

liblnk

Library and tools to access the Windows Shortcut File (LNK) format
C
188
star
9

libevtx

Library and tools to access the Windows XML Event Log (EVTX) format
C
184
star
10

libfsntfs

Library and tools to access the Windows New Technology File System (NTFS)
C
181
star
11

libvmdk

Library and tools to access the VMware Virtual Disk (VMDK) format
C
163
star
12

dtformats

Collection of data formats
Python
154
star
13

libfsrefs

Library and tools to access the Resilient File System (ReFS)
C
144
star
14

libvhdi

Library and tools to access the Virtual Hard Disk (VHD) image format
C
121
star
15

libvshadow

Library and tools to access the Volume Shadow Snapshot (VSS) format
C
107
star
16

libregf

Library and tools to access the Windows NT Registry File (REGF) format
C
102
star
17

libscca

Library and tools to access the Windows Prefetch File (SCCA) format.
C
67
star
18

libfwsi

Library to access the Windows Shell Item format
C
67
star
19

libolecf

Library and tools to access the OLE 2 Compound File (OLECF) format
C
67
star
20

libevt

Library and tools to access the Windows Event Log (EVT) format
C
56
star
21

libfwnt

Library for Windows NT data types
C
55
star
22

libqcow

Library and tools to access the QEMU Copy-On-Write (QCOW) image format
C
53
star
23

esedb-kb

Extensible Storage Engine (ESE) Database File Knowledge Base
Python
41
star
24

libexe

Library and tools to access the executable (EXE) format
C
39
star
25

libluksde

Library and tools to access LUKS Disk Encryption encrypted volumes
C
32
star
26

libmdmp

Library and tools to access the Windows Minidump (MDMP) format
C
32
star
27

libfshfs

Library and tools to access the Mac OS Hierarchical File System (HFS)
C
31
star
28

libnsfdb

Library and tools to access the Notes Storage Facility (NSF) database file format
C
29
star
29

libvslvm

Library and tools to access the Linux Logical Volume Manager (LVM) volume system format
C
28
star
30

assorted

Assorted documentation, scripts and tools
C
28
star
31

libsigscan

Library for binary signature scanning.
C
26
star
32

libfsclfs

Library and tools to access the Common Log File System (CLFS)
C
20
star
33

libodraw

Library and tools to access to optical disc (split) RAW image files (bin/cue, iso/cue)
C
19
star
34

libmodi

Library and tools to access the Mac OS disk image formats
C
18
star
35

libfsext

Library and tools to access the Extended File System
C
16
star
36

libmsiecf

Library and tools to access the Microsoft Internet Explorer (MSIE) Cache File (index.dat) files
C
16
star
37

winevt-kb

Windows Event Log Knowledge Base
Python
16
star
38

libfwevt

Library for Windows XML Event Log (EVTX) data types
C
16
star
39

libwtcdb

Library and tools to access the Windows (Vista/7) Explorer thumbnail cache database format (thumbcache.db)
C
15
star
40

libhibr

Library and tools to access the Windows Hibernation File (hiberfil.sys) format
C
13
star
41

libagdb

Library and tools to access the Windows SuperFetch database format
C
12
star
42

libvsmbr

Library and tools to access the Master Boot Record (MBR) volume system format
C
12
star
43

reviveit

ReviveIT (revit) is a proof of concept file recovery tool (carver)
11
star
44

libfole

Library for Object Linking and Embedding (OLE) data types
C
11
star
45

libcfile

Library for cross-platform C file functions
C
10
star
46

libfsxfs

Library and tools to access the SGI X File System (XFS)
C
10
star
47

libewf-legacy

Legacy version of libewf
C
10
star
48

libcaes

Library to support cross-platform AES encryption
C
10
star
49

libcthreads

Library for cross-platform C threads functions
C
9
star
50

libcdata

Library for cross-platform C generic data functions
C
9
star
51

documentation

Documentation
9
star
52

libhmac

Library to support various Hash-based Message Authentication Codes (HMAC)
C
9
star
53

libsmraw

Library and tools to access the (split) RAW image format
C
9
star
54

libvsgpt

Library and tools to access the GUID Partition Table (GPT) volume system format
C
9
star
55

libbfio

Library to provide basic file input/output abstraction
C
9
star
56

libfmos

Library for Mac OS data types
C
8
star
57

dtfabric

Tooling for data type and structure management
Python
8
star
58

libuna

Library to support Unicode and ASCII (byte string) conversions
C
8
star
59

libcnotify

Library for cross-platform C notification functions
C
8
star
60

libfplist

Library for plist format
C
7
star
61

libclocale

Library for cross-platform C locale functions
C
7
star
62

libcerror

Library for cross-platform C error functions
C
7
star
63

libftxf

Library for Transactional NTFS (TxF) data types
C
6
star
64

libbfoverlay

Library to provide basic file overlay support
C
6
star
65

libfguid

Library for GUID/UUID format
C
6
star
66

libcsplit

Library for cross-platform C split string functions
C
6
star
67

libcreg

Library and tools to access the Windows 9x/Me Registry File (CREG) format
C
5
star
68

libfdata

Library to provide generic file data functions
C
5
star
69

libfcrypto

Library for encryption formats
C
5
star
70

libfmapi

Library for Messaging API (MAPI) data types
C
5
star
71

libmapidb

Library to access the Exchange MAPI database format
C
5
star
72

vstools

Visual Studio tools for the libyal projects
Python
5
star
73

libfusn

Library for Update Sequence Number (USN) Journal data types
C
5
star
74

libfdatetime

Library for date and time formats
C
4
star
75

libsmdev

Library to access to storage media devices
C
4
star
76

testdata

Test data for libyal projects
4
star
77

libcpath

Library for cross-platform C path functions
C
4
star
78

libgzipf

Library and tools to access the GZIP file format
C
4
star
79

olecf-kb

OLE Compound File (OLECF) Knowledge Base
Python
4
star
80

libnk2

Library and tools to access the Microsoft Outlook Nickfile (NK2) format
C
4
star
81

libfcache

Library to provide generic file data cache functions
C
4
star
82

libcdatetime

Library for cross-platform C date and time functions
C
4
star
83

libwrc

Library to access the Windows Resource Compiler (WRC) format
C
3
star
84

libfsfat

Library and tools to access the File Allocation Table (FAT) file system
C
3
star
85

libcsystem

Library for cross-platform C system functions
C
3
star
86

libfwps

Library for Windows Property Store data types
C
3
star
87

libphdi

Library and tools to access the Parallels Hard Disk image format
C
3
star
88

libcdirectory

Library for cross-platform C directory functions
C
3
star
89

libftxr

Library for Transactional Registry (TxR) data types
C
2
star
90

legacy

Legacy releases
2
star
91

ideabucket

Idea bucket
2
star
92

libcstring

Library for cross-platform C string functions
C
2
star
93

libtableau

Library to read metadata from the Tableau(TM) forensic bridges (write blockers) based on tableau-parm
C
2
star
94

libfvalue

Library for generic file value functions
C
2
star
95

winsps-kb

Windows Serialized Property Store Knowledge Base
Python
2
star
96

libvsapm

Library and tools to access the Apple Partition Map (APM) volume system format
C
2
star
97

libovf

Library and tools to access the Open Virtualization Format (OVF)
1
star
98

plist-kb

Property list (plist) Knowledge Base
Python
1
star
99

winshl-kb

Windows Shell Knowledge Base
Python
1
star