Projects / RegLookup


The RegLookup project is devoted to direct analysis of Windows NT-based registry files. RegLookup provides command line tools, a C API, and a Python module for accessing registry data structures. The project has a focus on providing tools for digital forensic examiners (though it is useful for many purposes), and includes algorithms for retrieving deleted data structures from registry hives.

Operating Systems

Recent releases

  •  01 Oct 2011 19:25

    Release Notes: This bugfix release addresses some issues identified since the last release and includes no significant changes to functionality. Fixes include minor changes and fixes to Unicode handling in pyregfi, a correction for an infinite loop on corrupted registries, an added ldconfig call during installation, and improved error reporting.

    •  20 Jun 2011 03:15

      Release Notes: SK records and security descriptors are now accessible in pyregfi. Key caching was added to regfi, and SK caching was reintroduced. Minor API simplifications were made and documentation was improved. Numerous bugs were fixed.

      •  01 May 2011 16:44

        Release Notes: This 1.0 release candidate contains major improvements to regfi usability. regfi was made a proper library, and major improvements were made to the API. Python bindings (pyregfi) were added for regfi. The Make-based build system was replaced with a SCons-based one. Numerous improvements were made in regfi for multithreaded use and memory management. API documentation was improved.

        •  09 Mar 2010 03:57

          Release Notes: Big data support was improved and added to reglookup-recover. A -i option was added to reglookup for assisting with timeline generation. Unicode support was improved by correctly interpreting UTF-16LE key and value names. Data type interpretation was moved into regfi, and the regfi library interface was reorganized. regfi documentation was improved and Doxygen formatting was added.

          •  04 Jun 2009 00:40

            Release Notes: Experimental support for "big data" records. Experimental support cross-compiling to Windows using MinGW. Correctly handles known key flags. Overhauled memory allocation by switching to talloc. Many memory leaks have been fixed. Improved recovery rate in reglookup-recover with more modular parsing of deleted structures. Fixes for minor NULL pointer dereferences.


            Project Spotlight


            A Fluent OpenStack client API for Java.


            Project Spotlight

            TurnKey TWiki Appliance

            A TWiki appliance that is easy to use and lightweight.