Saturday, January 10, 2015

Editing a Windows Registry Under Linux

Forensicators frequently find themselves working with Windows systems under Linux. The hivex tools let you do that.

Under Fedora (tested under 20), a simple "yum install hivex" gives you the tools you need to navigate and dump registry files.