Notifications
Clear all

RegRipper on Linux?

13 Posts
8 Users
0 Reactions
2,819 Views
(@rampage)
Reputable Member
Joined: 17 years ago
Posts: 354
Topic starter  

Hello )

does anyone know if there is a port of regripper for linux? or other similar tools?

thnx in advice.


   
Quote
keydet89
(@keydet89)
Famed Member
Joined: 21 years ago
Posts: 3568
 

SIFT


   
ReplyQuote
(@rampage)
Reputable Member
Joined: 17 years ago
Posts: 354
Topic starter  

SIFT?

this SIFT?

https://forensics2.sans.org/community/downloads/

i can't see anything similar to regripper in the tools list, but maybe i'm just so tired that i'm getting blind..

i was looking for something to install on my existing OS i'm using on my forensic workstation.


   
ReplyQuote
keydet89
(@keydet89)
Famed Member
Joined: 21 years ago
Posts: 3568
 

This SANS blog post shows you what you need to do this
https://blogs.sans.org/computer-forensics/2009/02/06/regripper-ripping-registries-with-ease/


   
ReplyQuote
(@patrick4n6)
Honorable Member
Joined: 16 years ago
Posts: 650
 

Are Sans Portal accounts free? I was going to have a look at SIFT, but I balked when they ask for a billing address. I don't like to give billing info unless I actually intend to purchase something.


   
ReplyQuote
(@jeffbryner)
New Member
Joined: 16 years ago
Posts: 2
 

RegRipper is all perl, so it works on linux just fine as long as you have the required libraries (ParseWin32Registry)

and change the c\windows\perl references to linuxy /usr/bin/perl

No need to download 1.5Gig of SIFT just for that!

But if you like as far as I know SANS Portal accounts are free.


   
ReplyQuote
(@patrick4n6)
Honorable Member
Joined: 16 years ago
Posts: 650
 

I wasn't going to download SIFT for RegRipper, I already have 3 registry reporting solutions to choose from. I'm going to try out the whole thing when I get some free time. Thanks for confirming it's free.


   
ReplyQuote
(@hydrocloricacid)
Eminent Member
Joined: 16 years ago
Posts: 37
 

Have a look at this.

Regextract
Similar output to Reg ripper , there is a mono runtime which works fine under linux.

http//www.woany.co.uk/regextract/
Woany also has some other forensic tools which run under linux too. eg link file parser.

I have also used wine to run Regripper (the compiled exe) under linux with no problems.


   
ReplyQuote
(@twjolson)
Honorable Member
Joined: 17 years ago
Posts: 417
 

RegRipper is all perl, so it works on linux just fine as long as you have the required libraries (ParseWin32Registry)

and change the c\windows\perl references to linuxy /usr/bin/perl

No need to download 1.5Gig of SIFT just for that!

But if you like as far as I know SANS Portal accounts are free.

You may have to open the perl script files and resave them with Linux line endings, since the scripts where created on Windows, you'll get an error if you try to run them even if you chance the shebang line.


   
ReplyQuote
(@mrwh1t3)
Eminent Member
Joined: 15 years ago
Posts: 41
 

You can use the exe files with wine…but yeah, they are originally written in perl so you shouldn't have any issues.


   
ReplyQuote
Page 1 / 2
Share: