Harlan Carvey has managed to make a great new tool again: RipXP. RipXP is similar to rip.exe, in that it is a CLI tool and that it uses the same plugins as RegRipper and rip.exe. You give ripXP (as command line arguments) the hive file, the directory where the Restore Points reside, and a plugin to run. Once you have all this, ripXP will then:
- Access the hive file and guess what kind (SAM, System, NTUSER.DAT, Software, or Security) hive file it is (if it's an NTUSER.DAT file, it will attempt to retrieve the user's SID)
- Compare the type of hive file to the hive file that the plugin was written for; that is, if you pass it a System hive file, it won't let you run a plugin meant for an NTUSER.DAT file (just like rip.exe, ripXP includes the "-l" option so you can list all available plugins)
- Run the plugin against the hive file you selected
- Access the System Restore RP directories, and run the plugin against the appropriate hive
Download RipXP at http://www.regripper.net/
Recent Comments