Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade to RegRipper-3.0 and move it to tools folder #331

Closed
lfcnassif opened this issue Dec 7, 2020 · 9 comments · Fixed by #1316
Closed

Upgrade to RegRipper-3.0 and move it to tools folder #331

lfcnassif opened this issue Dec 7, 2020 · 9 comments · Fixed by #1316
Assignees
Projects

Comments

@lfcnassif
Copy link
Member

lfcnassif commented Dec 7, 2020

We should apply this fix sleuthkit/autopsy#6516 when upgrading. In current used version I've disabled shellext plugin in software plugin package because of an infinite loop years ago, not sure if it is the same.

@lfcnassif lfcnassif added this to To do in 4.0 via automation Oct 6, 2021
@lfcnassif lfcnassif removed this from To do in 4.0 Nov 4, 2021
@lfcnassif lfcnassif added this to To do in 4.1 via automation Sep 13, 2022
@lfcnassif lfcnassif self-assigned this Sep 13, 2022
@lfcnassif
Copy link
Member Author

lfcnassif commented Sep 13, 2022

Seems RegRipper-3.0 is MIT licensed, so we could move it to iped/tools folder without any license concerns.

@lfcnassif lfcnassif moved this from To do to In progress in 4.1 Sep 13, 2022
@lfcnassif
Copy link
Member Author

@tc-wleite, RegRipper-3.0 changed the date format to yyyy-MM-dd HH:mm:ss so the custom date localization code you added years ago won't be used anymore. Could I remove it and its localization strings? I think it may easy a bit future localization to other languages.

@wladimirleite
Copy link
Member

Sure!

@lfcnassif
Copy link
Member Author

lfcnassif commented Sep 13, 2022

I've forked RegRipper-3.0 repo and pushed some fixes to https://github.com/sepinf-inc/RegRipper3.0

@lfcnassif
Copy link
Member Author

I'll also collect some samples from our case database and run RegRipper-3.0 on them, since infinite loops in 2 regripper plugins used to happen in the past.

@lfcnassif
Copy link
Member Author

The run over ~125K registry format files from ~1500 cases finished, 2 timeouts were thrown, I'll take a closer look tomorrow...

@lfcnassif
Copy link
Member Author

2 timeouts were thrown

The hang is with the appcompatcache v.20200428 plugin when running on 2 SYSTEM files, it does not happen with regripper-2.8.

@lfcnassif lfcnassif changed the title Upgrade RegRipper Upgrade to RegRipper-3.0 Sep 14, 2022
@lfcnassif
Copy link
Member Author

The hang is with the appcompatcache v.20200428 plugin when running on 2 SYSTEM files, it does not happen with regripper-2.8.

pushed a quick and dirty workaround: sepinf-inc/RegRipper3.0@e7f8a07

@lfcnassif
Copy link
Member Author

I just found this with some important info about RegRipper-3.0:
http://windowsir.blogspot.com/2020/05/regripper-v30.html

One of them explains the decreased number of plugins:

As part of the process of "fixing" all 386 plugins in the 2.8 distro, a good number of them were updated, modified, consolidated, or simply "whacked"

So I'll stick with the default 3.0 plugins, and won't add the old (compatible) 2.8 ones, that can possibly duplicate a lot of info.

Another important info unknown to me until today is the plugins with _tln suffix, they are specific to generate a timeline output using the -aT switch! I'll open another ticket to parse the output of those plugins to populate our timeline.

4.1 automation moved this from In progress to Done Sep 14, 2022
@lfcnassif lfcnassif changed the title Upgrade to RegRipper-3.0 Upgrade to RegRipper-3.0 and move it to tools folder Jan 25, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
No open projects
4.1
Done
Development

Successfully merging a pull request may close this issue.

2 participants