Key | Value |
---|---|
MD5 | 4F655FF4A24DD166DAC0B539EFD57E16 |
PackageArch | x86_64 |
PackageDescription | Hive files are the undocumented binary blobs that Windows uses to store the Windows Registry on disk. Hivex is a library that can read and write to these files. 'hivexsh' is a shell you can use to interactively navigate a hive binary file. 'hivexregedit' lets you export and merge to the textual regedit format. 'hivexml' can be used to convert a hive file to a more useful XML format. In order to get access to the hive files themselves, you can copy them from a Windows machine. They are usually found in %systemroot%\system32\config. For virtual machines we recommend using libguestfs or guestfish to copy out these files. libguestfs also provides a useful high-level tool called 'virt-win-reg' (based on hivex technology) which can be used to query specific registry keys in an existing Windows VM. For Perl bindings, see 'perl-hivex'. For Python bindings, see 'python-hivex'. |
PackageMaintainer | Fedora Project |
PackageName | hivex |
PackageRelease | 6.el5 |
PackageVersion | 1.3.5 |
SHA-1 | 01AFF7F524493CD973626C2043421B2BE1CCEE66 |
SHA-256 | 67F246E7E898AB5B772FADCFA971C49EFBBCD074AD57696890E74C7B59D5A1B8 |
hashlookup:children-total | 26 |
hashlookup:trust | 50 |
The searched file hash includes 26 children files known and seen by metalookup. A sample is included below:
Key | Value |
---|---|
FileName | ./usr/share/locale/gu/LC_MESSAGES/hivex.mo |
FileSize | 4942 |
MD5 | 25952A682966B2623FEBC4660C8605D2 |
SHA-1 | 00F33475BB4282A003952BD4983D3810F69C6469 |
SHA-256 | D3D32D5F8DAE4B1474F8AC25BF671481E9C1B3EE1D49C7F0D65CD2258DFE459E |
SSDEEP | 96:LkW8G+KGUw0iqCQVWAKrworHLx9SlKGn6FU/BrPWv:wW8xeuQclr5rH1IlKobWv |
TLSH | T1E7A101C0C7A8E532E6D75EBA838D421096685747CD6A6300128DDD45AD42CEE3FFE9CB |
Key | Value |
---|---|
FileName | ./usr/share/man/man1/hivexml.1.gz |
FileSize | 2562 |
MD5 | 54416BAAB7D94E4800463429ACC0C71C |
SHA-1 | 08434FAC9DA8CCB8405527E259E2205EA8D90F6F |
SHA-256 | CADE8C172C45541B68EAD7BC67A048B073A186A8912BA8CDC6F9DC79DFD03A5C |
SSDEEP | 48:Xn+3VTXT5Ykpz9btj/epnB8vJz1a2kjPsuU4Pov9I247ZOAwHvLQhrinL/:3+3VTXT5YkxN4VjPs6V7sAwjHT |
TLSH | T1D051391445DA8F93E1F1C2BAB1F79EC1AF1E89A196931AB1DDFC1A221D04E13204408E |
Key | Value |
---|---|
CRC32 | AEFA18C6 |
FileName | README |
FileSize | 3067 |
MD5 | F9107B889B57B930F7B70452E196BA86 |
OpSystemCode | 362 |
ProductCode | 183357 |
SHA-1 | 1A4B105C1CAF3F16716EFA21236B786A7CBCB758 |
SHA-256 | CC5DB02C966F3745D2DD90BC66DE6E870A304D4CEA441F80C82B6F00370F6837 |
SSDEEP | 48:t2lyXyvv18eGFxqqsfS2P/tL3hITBjvDoSox5vDrzGhN3/Jkd5dHUcNzv:oyXWKfBsfptLGvDKxYXPAHUAzv |
SpecialCode | |
TLSH | T16C5195366EA8837363F0D6B0520EC2B5CB26853D9A3F55D2597C404AB322DA162FD3F0 |
db | nsrl_modern_rds |
insert-timestamp | 1646988226.3800511 |
source | NSRL |
Key | Value |
---|---|
CRC32 | EA01DC1A |
FileName | usr/bin/hivexget |
FileSize | 1035 |
MD5 | 9A3D08CCB414EF5820F15E60ADD5FABA |
OpSystemCode | 362 |
ProductCode | 183705 |
SHA-1 | 224CCF0E3E7A7D7276A233F4F6194D4873EBEF1E |
SHA-256 | 48FEE0A09A84DE9F91687F2471B8CFBD59CE3152DE08E61268539F4D005499B3 |
SSDEEP | 24:oct2HSCUgiyUVOkHxHqTbV3oDq9e4IOJpWeu:onyzjyUjH0uqQ4IEMeu |
SpecialCode | |
TLSH | T17A11758D3081C3B6880402E83A0A61DEA12D579F6B6D1464700DE25EEF05FB655F26D8 |
db | nsrl_modern_rds |
insert-timestamp | 1646991339.9974313 |
source | NSRL |
tar:gname | root |
tar:uname | root |
Key | Value |
---|---|
FileName | ./usr/share/locale/nl/LC_MESSAGES/hivex.mo |
FileSize | 4425 |
MD5 | 965ED32214DDF104CA4F200C572AD517 |
SHA-1 | 249F0C57665E29A3870DB3DF8A13BD46B14BBEC2 |
SHA-256 | 8162AC399CD81B736BF19067088E414CDDF2D37A6CA04748FD7DE4D4992878E1 |
SSDEEP | 96:7/MRkWXhG+KmJVdY1Uw0iqCQVimlx00B8OgURYGmgx1Z9:4SWxx1SOuQIK5KvWp |
TLSH | T18691D70B8B802A6FCBD711F2E74DC242958401289EB6D265295CC57279C0DBE52FF0DC |
Key | Value |
---|---|
FileName | ./usr/share/locale/hi/LC_MESSAGES/hivex.mo |
FileSize | 5571 |
MD5 | 2B41EBDFC8257E89A187EA0719F3AFB2 |
SHA-1 | 26B9F09F320D5C7215BA2A2F5AF838E3A9C71385 |
SHA-256 | E90E17F42D5BCEAFF5A425C23D3B8208A72B4465B5FE07352CE363C505CF41E3 |
SSDEEP | 96:7/RkikWXhG+KmJVdY1Uw0iqCQu8kWvdq+rMA+BCfhSRpv4aXY5av0Xv0bG+K2Ant:1CWxx1SOuQgWvPeQhSRpffxGwQV |
TLSH | T190B1544CE7E877B6DEED34B6374C4633C4581678ABA642510998B3C7B980CB814BF1CA |
Key | Value |
---|---|
FileName | ./usr/bin/hivexml |
FileSize | 19392 |
MD5 | C44807A5BD71F1502ED5845A9DB2FDF6 |
SHA-1 | 2B23131295D3E29C7B3775001FC25DC32ECB4B4E |
SHA-256 | 19964761AD6ED31513898EA4C1C93A361F686E8452D654739D56126081A94A29 |
SSDEEP | 192:GoKJcOjj1Rn5nVL175ECNTTa5HIILP+Ii/3vd7En7/83p6mw5VS4SywW29llZ45l:iJcSn5nVxNAy6n7/83O5Mic9tM |
TLSH | T16592D843DE5154BBC996C334589AA23419B3B5B8BB397E174400BB712E21BAC4F0FF29 |
Key | Value |
---|---|
FileName | ./usr/share/man/man1/hivexsh.1.gz |
FileSize | 5353 |
MD5 | B1682DBF96A7DB3E905F2C9565FFF1E2 |
SHA-1 | 42952035A874D60C3F33F42A0824CBE1EB1BEAC1 |
SHA-256 | 26CD6A31ABE0DAEAC1EF44840DB0CA12AA7BB7CDFAE891EBFEBFF2B5C53C22C2 |
SSDEEP | 96:Bmx3HUtcPOBdudv3txb/Hz1nioPzc9591NJML0pmDCejfprW5iWfztZBV6SD/Hp2:rD03b/He/DNOg4d16fzBV6SDv1R29 |
TLSH | T184B17D631632B19932E7BF5F61D10A71F0FF773F6FBA9918AD1B87C8045A8D19482140 |
Key | Value |
---|---|
FileName | ./usr/share/man/man1/hivexregedit.1.gz |
FileSize | 4935 |
MD5 | 6EDAA39BE6666593910D6D18652EB662 |
SHA-1 | 4455E451377073C61E4414C8ABB23B78EA4BD7DE |
SHA-256 | 57D3FC1DE6DE5ED4F7220C42D9838F3D2221F26DB97D7D28352C3FA366E15FA1 |
SSDEEP | 96:/rDSkKw/w5MdKVyZEDIhYjX9mopHYZ18kAxiRyhXsuV8qt0i9lBTYrS:/K2JZXhu95pHMekNRChJrPBZ |
TLSH | T114A17C442EC98624242812F4A15BEDCBF5FEC65C92B11396CEECF08472F586517D59E2 |
Key | Value |
---|---|
FileName | ./usr/share/man/man1/hivexget.1.gz |
FileSize | 3019 |
MD5 | C4D2AEACBD0238C739F0B9191E83F30B |
SHA-1 | 5222711B0CC20578A90DB5BEA96F7D3951446C98 |
SHA-256 | FAFF5A19C12D60D630B1BA314AD05CB51E1EBF3FC639DBB0CB09EE526D96940F |
SSDEEP | 48:XIyR9XXk7PG8mMzaDQ79SU8RdaJdyK7qStxx4PzxZCnI14PGW5a:/R9yPGdMT/8RsmswrIIWs |
TLSH | T100514AA62DAE66564F2A41B2338C4C443EE8B8DE353033D188BE1D700347E5E06DA13B |