Key | Value |
---|---|
MD5 | 6575772DADB45B004DE883C327DAD210 |
PackageArch | armv7hl |
PackageDescription | Hive files are the undocumented binary blobs that Windows uses to store the Windows Registry on disk. Hivex is a library that can read and write to these files. 'hivexsh' is a shell you can use to interactively navigate a hive binary file. 'hivexregedit' lets you export and merge to the textual regedit format. 'hivexml' can be used to convert a hive file to a more useful XML format. In order to get access to the hive files themselves, you can copy them from a Windows machine. They are usually found in %systemroot%\system32\config. For virtual machines we recommend using libguestfs or guestfish to copy out these files. libguestfs also provides a useful high-level tool called 'virt-win-reg' (based on hivex technology) which can be used to query specific registry keys in an existing Windows VM. For OCaml bindings, see 'ocaml-hivex-devel'. For Perl bindings, see 'perl-hivex'. For Python bindings, see 'python-hivex'. For Ruby bindings, see 'ruby-hivex'. |
PackageMaintainer | Fedora Project |
PackageName | hivex |
PackageRelease | 4.fc17 |
PackageVersion | 1.3.5 |
SHA-1 | 0941F255166E27C5FBC3D629FF971C362D3CE5CE |
SHA-256 | BE12BD15F2050A21E50CB83CE93A8C36D17B43EA7B9F62C2218C47A10F48752E |
hashlookup:children-total | 26 |
hashlookup:trust | 50 |
The searched file hash includes 26 children files known and seen by metalookup. A sample is included below:
Key | Value |
---|---|
FileName | ./usr/share/locale/gu/LC_MESSAGES/hivex.mo |
FileSize | 4942 |
MD5 | 25952A682966B2623FEBC4660C8605D2 |
SHA-1 | 00F33475BB4282A003952BD4983D3810F69C6469 |
SHA-256 | D3D32D5F8DAE4B1474F8AC25BF671481E9C1B3EE1D49C7F0D65CD2258DFE459E |
SSDEEP | 96:LkW8G+KGUw0iqCQVWAKrworHLx9SlKGn6FU/BrPWv:wW8xeuQclr5rH1IlKobWv |
TLSH | T1E7A101C0C7A8E532E6D75EBA838D421096685747CD6A6300128DDD45AD42CEE3FFE9CB |
Key | Value |
---|---|
FileName | ./usr/share/man/man1/hivexget.1.gz |
FileSize | 3025 |
MD5 | E74EF7931B39521F84CA53A6DA3C2844 |
SHA-1 | 05B8D08C336E8643FE348F9A767F292C61CF2877 |
SHA-256 | E9FBF67BAE48B745063DD318CDCA00934AB8B989856810CCA6A5789F143D0AA0 |
SSDEEP | 48:XpZ4aE9f3btQd3mM2sYU8T5DDV6/VMMw3fVYx76/ewKsb+8CQAn/OkKJAO5v1qS2:XA13btW3L8F56qfVYx9rcAn/2AO5v9On |
TLSH | T114515C01022F64414614912ED7ABC4A1396BBB60FDCBABF9D665A2C338CF90FD1E5E50 |
Key | Value |
---|---|
FileName | ./usr/bin/hivexml |
FileSize | 18096 |
MD5 | EE3066C1E04372D95DC9AF1B074F197B |
SHA-1 | 13BFD9168CE3F7B47FC17037EBF31D6F9EFF9872 |
SHA-256 | 7D59102325BC1DCC528672D888E75976AFE6FFA1694B3BACA3A6D82A24DB04BF |
SSDEEP | 384:32n7SFnyFA1IZVUr/8bol7ogaBWdlHprGKg:HFyy1r/8boByApg |
TLSH | T14382B72876E39967CFC007B57E0F9F64227163AAEBBA3B039B44C155324709D8E53E19 |
Key | Value |
---|---|
FileName | ./usr/share/man/man1/hivexsh.1.gz |
FileSize | 5347 |
MD5 | 7C45C48985047230CF59F0D457C5851E |
SHA-1 | 1713B7E33BC908C7923EB2AF2A516965076F5688 |
SHA-256 | 0808CA55C359B4C5602D775DBCC80F8CDA84D3AEC96A00E4E1E242E3C263DD12 |
SSDEEP | 96:QTIyzpvLli5c4kEbPKneg1pVrwkCGyp+yQGj/tQg1u3jCbmMnthdUOTXtuandmb:4I4pxi5c4kdegplC/+wogZvhTUb |
TLSH | T1E2B19FA14BCC0549B2BE9327620BD7367C73D4DF33595150DAF7B23215BA681C15D472 |
Key | Value |
---|---|
CRC32 | AEFA18C6 |
FileName | README |
FileSize | 3067 |
MD5 | F9107B889B57B930F7B70452E196BA86 |
OpSystemCode | 362 |
ProductCode | 183357 |
SHA-1 | 1A4B105C1CAF3F16716EFA21236B786A7CBCB758 |
SHA-256 | CC5DB02C966F3745D2DD90BC66DE6E870A304D4CEA441F80C82B6F00370F6837 |
SSDEEP | 48:t2lyXyvv18eGFxqqsfS2P/tL3hITBjvDoSox5vDrzGhN3/Jkd5dHUcNzv:oyXWKfBsfptLGvDKxYXPAHUAzv |
SpecialCode | |
TLSH | T16C5195366EA8837363F0D6B0520EC2B5CB26853D9A3F55D2597C404AB322DA162FD3F0 |
db | nsrl_modern_rds |
insert-timestamp | 1646988226.3800511 |
source | NSRL |
Key | Value |
---|---|
CRC32 | EA01DC1A |
FileName | usr/bin/hivexget |
FileSize | 1035 |
MD5 | 9A3D08CCB414EF5820F15E60ADD5FABA |
OpSystemCode | 362 |
ProductCode | 183705 |
SHA-1 | 224CCF0E3E7A7D7276A233F4F6194D4873EBEF1E |
SHA-256 | 48FEE0A09A84DE9F91687F2471B8CFBD59CE3152DE08E61268539F4D005499B3 |
SSDEEP | 24:oct2HSCUgiyUVOkHxHqTbV3oDq9e4IOJpWeu:onyzjyUjH0uqQ4IEMeu |
SpecialCode | |
TLSH | T17A11758D3081C3B6880402E83A0A61DEA12D579F6B6D1464700DE25EEF05FB655F26D8 |
db | nsrl_modern_rds |
insert-timestamp | 1646991339.9974313 |
source | NSRL |
tar:gname | root |
tar:uname | root |
Key | Value |
---|---|
FileName | ./usr/share/locale/nl/LC_MESSAGES/hivex.mo |
FileSize | 4425 |
MD5 | 965ED32214DDF104CA4F200C572AD517 |
SHA-1 | 249F0C57665E29A3870DB3DF8A13BD46B14BBEC2 |
SHA-256 | 8162AC399CD81B736BF19067088E414CDDF2D37A6CA04748FD7DE4D4992878E1 |
SSDEEP | 96:7/MRkWXhG+KmJVdY1Uw0iqCQVimlx00B8OgURYGmgx1Z9:4SWxx1SOuQIK5KvWp |
TLSH | T18691D70B8B802A6FCBD711F2E74DC242958401289EB6D265295CC57279C0DBE52FF0DC |
Key | Value |
---|---|
FileName | ./usr/share/locale/hi/LC_MESSAGES/hivex.mo |
FileSize | 5571 |
MD5 | 2B41EBDFC8257E89A187EA0719F3AFB2 |
SHA-1 | 26B9F09F320D5C7215BA2A2F5AF838E3A9C71385 |
SHA-256 | E90E17F42D5BCEAFF5A425C23D3B8208A72B4465B5FE07352CE363C505CF41E3 |
SSDEEP | 96:7/RkikWXhG+KmJVdY1Uw0iqCQu8kWvdq+rMA+BCfhSRpv4aXY5av0Xv0bG+K2Ant:1CWxx1SOuQgWvPeQhSRpffxGwQV |
TLSH | T190B1544CE7E877B6DEED34B6374C4633C4581678ABA642510998B3C7B980CB814BF1CA |
Key | Value |
---|---|
FileName | ./usr/share/man/man1/hivexml.1.gz |
FileSize | 2575 |
MD5 | FCBA60EE092E7E11DEB1382843CD5824 |
SHA-1 | 43094EFE0046CEE5F75006B9D5548C09474273C5 |
SHA-256 | 28007012EE9201242AFDBA5A3BC941C69C1E952731935B23B93323006AF6FA37 |
SSDEEP | 48:XIXVU5yf7vlwcEzW/LfCh7i5/UJpd1eu26rEnL3rxILCjoE1:2U5yjvlwcSph7iU1x26rgvxI8oE1 |
TLSH | T1AD511A775B12E88178534C255A4B34D1B788AAA01FB2E2E9134EB7263447050F37A1A5 |
Key | Value |
---|---|
FileName | ./usr/bin/hivexsh |
FileSize | 26368 |
MD5 | 5126DB84B999C679CB85521C28F5CAAD |
SHA-1 | 514FBA8CC135968FF73748F21892EB47B25C1312 |
SHA-256 | 37D321F47FFCE4F2D1BA6685DA2D843EB4A993B0518389EA2C723EC2081931E2 |
SSDEEP | 768:c5zJ3sV9lN1dFtV9lN1dFtV9lqS6iKyaCqS6iKyaCqS6iKyaCqS6iKyaCjLzbDr4:c5yV9lN1dFtV9lN1dFtV9lqS6iKyaCqC |
TLSH | T1A3C2E78571D15EA7C5C01A76FE4FAF58336243E4D79E33068B0052632986A5B8F3FB4A |