A tale on RegRipper Plugins unnoticed
Last weeks... it cames out that some RegRipper Plugins have errors and/or do not parse correctly/at all the desired keys. This fact should not be unexpected since there exist many plugins (from far less many contributors, unfortunately) and since they should work on xp-(s)vista-7 Windows OSes: errors are around the corner. What is really unexpected is the delay with which they were detected by the DFIR community (included me, of course). Let's start with the first cas e. timezone.pl This plugin " accesses the System hive file to get the contents of the TimeZoneInformation key ", and it's one of the first-most important information I usually get from the System hive, since I need to understand when things happened. That's the output coming from version 20110901 , executed on a XP system: Launching timezone v.20110901 timezone v.20110901 (System) Get TimeZoneInformation key contents TimeZoneInformation key ControlSet001\Control