Key | Value |
---|---|
MD5 | 889D0E52C6753610ACDC14E131D8FB8E |
PackageArch | ppc64 |
PackageDescription | Hive files are the undocumented binary files that Windows uses to store the Windows Registry on disk. Hivex is a library that can read and write to these files. 'hivexsh' is a shell you can use to interactively navigate a hive binary file. 'hivexregedit' lets you export and merge to the textual regedit format. 'hivexml' can be used to convert a hive file to a more useful XML format. In order to get access to the hive files themselves, you can copy them from a Windows machine. They are usually found in %systemroot%\system32\config. For virtual machines we recommend using libguestfs or guestfish to copy out these files. libguestfs also provides a useful high-level tool called 'virt-win-reg' (based on hivex technology) which can be used to query specific registry keys in an existing Windows VM. For OCaml bindings, see 'ocaml-hivex-devel'. For Perl bindings, see 'perl-hivex'. For Python bindings, see 'python-hivex'. For Ruby bindings, see 'ruby-hivex'. |
PackageMaintainer | Fedora Project |
PackageName | hivex |
PackageRelease | 3.fc20 |
PackageVersion | 1.3.8 |
SHA-1 | B4779E55D8A7BB1C98D2F31BFE3BBD094E12CF57 |
SHA-256 | 8564ADEED2109348D3010C4F73CDB12F5C8DA4B3AD75CAF3C0EDBAC9FDDC8748 |
hashlookup:children-total | 26 |
hashlookup:trust | 50 |
The searched file hash includes 26 children files known and seen by metalookup. A sample is included below:
Key | Value |
---|---|
FileName | ./usr/share/locale/or/LC_MESSAGES/hivex.mo |
FileSize | 708 |
MD5 | BF01DC45C007A6DA55E17C20230B52CC |
SHA-1 | 0A4A0E31FD3B527B71496615D4F6535F60D52140 |
SHA-256 | F5B456A83F577B518A2FF698155691A79BF34FE51350875AF635CA9D172D2424 |
SSDEEP | 12:iCAuzk25UMAHAl68Oit0jDxnq5wn/0cQzlwxEXmBQWiOWOgD6HqqnagP+qhi:/Auz95UMew68Oit0jDxq5+0c0qEXmGIU |
TLSH | T1CE012340E8F48D10D6DC30F283C4C33832580796FADBE9CA290A94A62FD6AFD06FD644 |
Key | Value |
---|---|
FileName | ./usr/share/locale/nl/LC_MESSAGES/hivex.mo |
FileSize | 4425 |
MD5 | B5CAFACB4A73C9DCA12F1BE8045F6856 |
SHA-1 | 0B0798027672101AC5C7847E47FF82AA6E06F8CD |
SHA-256 | E49ACA63DA44569D5C6038BF99753736E643C1F5AE614D448426B8EADFB711EE |
SSDEEP | 96:7/MRkWXhG+KmJVdY1Uw0iqCkVimlx00B8OgURYGmgx1Z9:4SWxx1SOukIK5KvWp |
TLSH | T1DF91D70B8B802A6FCBD711F2E74DC2429584012C9EB6D2A5295CC57279C0CBE52FF0DC |
Key | Value |
---|---|
FileName | ./usr/share/locale/ru/LC_MESSAGES/hivex.mo |
FileSize | 5463 |
MD5 | FD8038FA90AFF9BB2D566F60BE9A248C |
SHA-1 | 0E6C3138F9D81BD918D31705BD24E092127042C5 |
SHA-256 | 1BB9CEFDAD21EBB69C680888886A01C54AA3A669A05BF4C1D4682D7A05CF4AA3 |
SSDEEP | 96:7/urkWXhG+KmJVdY1Uw0iqCkKrzQ9IZ65sgw2OLDGBkLo12+rx8TFxxgDnn:iQWxx1SOukRPsgwFLamLo1PxAXxgDnn |
TLSH | T10BB183114B893DAFD6567177CA08AA097DD704FE3FBA93501618986F30E2478873F28C |
Key | Value |
---|---|
CRC32 | EA01DC1A |
FileName | usr/bin/hivexget |
FileSize | 1035 |
MD5 | 9A3D08CCB414EF5820F15E60ADD5FABA |
OpSystemCode | 362 |
ProductCode | 183705 |
SHA-1 | 224CCF0E3E7A7D7276A233F4F6194D4873EBEF1E |
SHA-256 | 48FEE0A09A84DE9F91687F2471B8CFBD59CE3152DE08E61268539F4D005499B3 |
SSDEEP | 24:oct2HSCUgiyUVOkHxHqTbV3oDq9e4IOJpWeu:onyzjyUjH0uqQ4IEMeu |
SpecialCode | |
TLSH | T17A11758D3081C3B6880402E83A0A61DEA12D579F6B6D1464700DE25EEF05FB655F26D8 |
db | nsrl_modern_rds |
insert-timestamp | 1646991339.9974313 |
source | NSRL |
tar:gname | root |
tar:uname | root |
Key | Value |
---|---|
FileName | ./usr/share/man/man1/hivexml.1.gz |
FileSize | 2646 |
MD5 | A20ED42F3C8ADB64A46ABDB9E80D60FE |
SHA-1 | 277F06DB0BD10398B6F7E2740AECC9E1AA7069C1 |
SHA-256 | DADA222C7630AE18E0C39E5DAB99F9AC73C0E98CD7282B0D968AC500D631AC72 |
SSDEEP | 48:XIlyJ3MB4cjj2NpCRCYN3pjzQJr1QfXX+loWsfVBK8behdvnTsaxQh:8C3bcjj2nCLNWCf9WsfTK8ybvTsaM |
TLSH | T170513CC5CB4B52802BEE907562CB31EA19E0569C2487E3CB90D624E551D5289263C9AC |
Key | Value |
---|---|
FileName | ./usr/share/locale/hi/LC_MESSAGES/hivex.mo |
FileSize | 5571 |
MD5 | 73F5379D6185BD94094BD9E013AF2F2D |
SHA-1 | 380662E160D65696FCDDD5BE5A3DC0E88361A745 |
SHA-256 | 9228E3FF34CA3ACDC76E63E4EF1F17317ED4F043744358C30199F992A9C6FAF0 |
SSDEEP | 96:7/RkikWXhG+KmJVdY1Uw0iqCku8kWvdq+rMA+BCfhSRpv4aXY5av0Xv0bG+K2Ant:1CWxx1SOukgWvPeQhSRpffxGwQV |
TLSH | T1C5B1434CE7E977B6DAED38B6374C4532C4581678ABA642510998B3C7B980CB814BF1CA |
Key | Value |
---|---|
CRC32 | D8D508F1 |
FileName | ./usr/lib64/libhivex.so.0 |
FileSize | 17 |
MD5 | 1C188DB0D174433E088998AC1AC46E09 |
OpSystemCode | 362 |
ProductCode | 183357 |
RDS:package_id | 222721 |
SHA-1 | 59A879F3C5F7B0A74DA1855A929ED9A0A6BE0362 |
SHA-256 | A1A7161FD991FD7DF8EE8E6A798A4AE610B3AD5C08929BC69CED04A83B57EB7C |
SSDEEP | 3:ENSahD:EMUD |
SpecialCode | |
TLSH | |
db | nsrl_modern_rds |
insert-timestamp | 1727040645.1441815 |
source | RDS.db |
Key | Value |
---|---|
CRC32 | EB688BD6 |
FileName | ./usr/share/licenses/ocaml-hivex/LICENSE |
FileSize | 26650 |
MD5 | F23A23B996E90732D119709C8ACA08DB |
OpSystemCode | 362 |
ProductCode | 183705 |
RDS:package_id | 263813 |
SHA-1 | 5A02CDEBBDCDF259EF79A175339B33608E4BC345 |
SHA-256 | AA9BAA29E495877229E89F517D381672586F7233CCFCC7C0DEFA30FFBAAF3C65 |
SSDEEP | 384:U456OuAbnn0UReX6wFDVxnFw7xqsvzt+z/k8E9HinIhFkspcM9bc7ups0CZuQa:U45trLeDnFMz1ReScmc7GshZuQa |
SpecialCode | |
TLSH | T1BBC2853EB70103B206C206906A4FA4DEE32BD07932675964749DC15D23AB93543FFBEA |
db | nsrl_modern_rds |
insert-timestamp | 1654960987.863141 |
source | modern.db |
Key | Value |
---|---|
FileName | ./usr/share/locale/uk/LC_MESSAGES/hivex.mo |
FileSize | 6008 |
MD5 | 6FA8566583EF5A77E7BB4E1416DEAA2A |
SHA-1 | 646AE8EFE99B9A0461C5021714358E1628CCC6C2 |
SHA-256 | 6AB3F59388A9DAD6C5BB23D7B13C21D7A0D05C68BC99945AA5E099E43A1B586D |
SSDEEP | 96:7/zz6kkWXhG+KmJVdY1Uw0iqCkpjGbV7sl4G9ss0pTsxnwVqS0L77GiMYibFUOwP:r6ZWxx1SOukwNyt0p4xwVqSwGiMY4FUx |
TLSH | T1A9C131219B9958DFC626A1B7D548B9047DDB00FE7FB2831222689DBF39E1068457D38C |
Key | Value |
---|---|
FileName | ./usr/bin/hivexml |
FileSize | 69600 |
MD5 | 5C12FB05340C9B92484F582559FBD3EC |
SHA-1 | 7D1DE00DE66DE8A5EC433DC8A63EB0598CD01F01 |
SHA-256 | 8CE038420C364A52814158CBAA5DF9B016CC42A409D649497168033E8CB084A7 |
SSDEEP | 384:hZbqoE8rT1WhECQ9bpwHi//DoDGAIrvb97lrdYEpmDRCzPfTc:DBw4Nm4dEDAY |
TLSH | T19D6392EC7B95CA23C7580238E5921B3CE37C9D50D522754ABE0F936500F2A9D68BEBD1 |