Parser for Windows registry that supports current and old installations/upgrades. This could be helpful in digital forensics and investigations. I considered this beta I've tested this on 10+ installations without a problem.
Current operating system information is located in SOFTWARE\Microsoft\Windows NT\CurrentVersion
The old installations are located SYSTEM\Setup\Source OS (Updated on xx/xx/xxxx xx:xx:xx)
Coded in Python3.
WinOSparser.py SYSTEM SOFTWARE
or
python3 WinOSparser.py SYSTEM SOFTWARE
Prerequisites
Python3
Windows Registry python library from Willi Ballenthin (included)
Install
git clone https://github.com/dfirdoctor/WinOSparser.git
https://github.com/dfirdoctor/WinOSparser/archive/master.zip
Willi Ballenthin (Windows Registry library)
Glenn P. Edwards Jr (reused code)