SEARCH
NEW RPMS
DIRECTORIES
ABOUT
FAQ
VARIOUS
BLOG

 
 

registrydecoder rpm build for : Fedora 22. For other distributions click registrydecoder.

Name : registrydecoder
Version : 20120816 Vendor : cert_org
Release : 1.fc22 Date : 2015-06-01 16:57:44
Group : Applications/Forensics Tools Source RPM : registrydecoder-20120816-1.fc22.src.rpm
Size : 1.41 MB
Packager : Lawrence R_ Rogers (lrr_cert_org)
Summary : registrydecoder - automates acquisition, analysis, and reporting of Microsoft Windows registry contents.
Description :
This version of the Registry Decoder performs offline analysis (on an
investigator’s lab machine) of acquired registry files. This project
can be found here. The current version of this tool can process raw disk
images, partition images, individual registry files, and the database
of hives acquired by the online component. When given a disk image,
the Sleuthkit libraries are used to parse the image and read each
registry hive. This includes the ability to acquire historical files
from System Restore Points as well as the RegBack folder of Vista and
7 images. Individual registry hives are processed using libraries from
the RegLookup project.

After being provided with all registry-oriented evidence for a particular
case, which can be any combination of registry files, disk images, and
acquired databases, Registry Decoder performs a one-time pre-processing
of the evidence. During this process, it creates a number of databases and
metadata files that contain all information needed to analyze the files.

The analysis section of the offline component contains a number of
powerful features. The first feature is Search, which allows for powerful
searching across registry hives. The searching abilities include:

* Filtering by hive keys, name, and data
* Filtering by the last write time of keys
* Searching individual terms or with a newline delimited search term file
* Exact or wildcard based search
* Viewing of search results
* Automated reporting of search contents to HTML, PDF, or XLS

RPM found in directory: /mirror/vol2/forensics.cert.org/fedora/cert/22/i386

Content of RPM  Changelog  Provides Requires

Hmm ... It's impossible ;-) This RPM doesn't exist on any FTP server

Provides :
registrydecoder
registrydecoder(x86-32)

Requires :
sleuthkit
rpmlib(FileDigests) <= 4.6.0-1
rpmlib(CompressedFileNames) <= 3.0.4-1
rpmlib(PartialHardlinkSets) <= 4.0.4-1
python(abi) = 2.7
/usr/bin/python
rpmlib(PayloadIsXz) <= 5.2-1
python-xlwt
/bin/bash
rpmlib(PayloadFilesHavePrefix) <= 4.0-1
PyQt4
pytsk
python-reportlab
reglookup


Content of RPM :
/usr/bin/registrydecoder
/usr/lib/python2.7/site-packages/registrydecoder/GUI/__init__.py
/usr/lib/python2.7/site-packages/registrydecoder/GUI/__init__.pyc
/usr/lib/python2.7/site-packages/registrydecoder/GUI/__init__.pyo
/usr/lib/python2.7/site-packages/registrydecoder/GUI/caseanalysis.py
/usr/lib/python2.7/site-packages/registrydecoder/GUI/caseanalysis.pyc
/usr/lib/python2.7/site-packages/registrydecoder/GUI/caseanalysis.pyo
/usr/lib/python2.7/site-packages/registrydecoder/GUI/convui.sh
/usr/lib/python2.7/site-packages/registrydecoder/GUI/createcase.py
/usr/lib/python2.7/site-packages/registrydecoder/GUI/createcase.pyc
/usr/lib/python2.7/site-packages/registrydecoder/GUI/createcase.pyo
/usr/lib/python2.7/site-packages/registrydecoder/GUI/filetab.py
/usr/lib/python2.7/site-packages/registrydecoder/GUI/filetab.pyc
/usr/lib/python2.7/site-packages/registrydecoder/GUI/filetab.pyo
/usr/lib/python2.7/site-packages/registrydecoder/GUI/generate_forms.py
/usr/lib/python2.7/site-packages/registrydecoder/GUI/generate_forms.pyc
/usr/lib/python2.7/site-packages/registrydecoder/GUI/generate_forms.pyo
/usr/lib/python2.7/site-packages/registrydecoder/GUI/guicommon.py
/usr/lib/python2.7/site-packages/registrydecoder/GUI/guicommon.pyc
/usr/lib/python2.7/site-packages/registrydecoder/GUI/guicommon.pyo
/usr/lib/python2.7/site-packages/registrydecoder/GUI/oldforms/exportall.ui
/usr/lib/python2.7/site-packages/registrydecoder/GUI/pathtab.py
/usr/lib/python2.7/site-packages/registrydecoder/GUI/pathtab.pyc
/usr/lib/python2.7/site-packages/registrydecoder/GUI/pathtab.pyo
/usr/lib/python2.7/site-packages/registrydecoder/GUI/plugintab.py
/usr/lib/python2.7/site-packages/registrydecoder/GUI/plugintab.pyc
/usr/lib/python2.7/site-packages/registrydecoder/GUI/plugintab.pyo
/usr/lib/python2.7/site-packages/registrydecoder/GUI/reportfuncs.py
/usr/lib/python2.7/site-packages/registrydecoder/GUI/reportfuncs.pyc
/usr/lib/python2.7/site-packages/registrydecoder/GUI/reportfuncs.pyo
There is 279 files more in these RPM.

 
ICM