Full Disclosure mailing list archives

Re: Re: Windows Registry Analzyer


From: Michael Holstein <michael.holstein () csuohio edu>
Date: Thu, 03 Mar 2005 15:43:17 -0500


  Yes, absolutely.  It's called "InCtrl5" and it is *exactly* what you both
want.

Found it :

http://publicdata.home.comcast.net/inctrl5.zip

Also note : this is Plugin #56 on PartPE (which would be quite useful for forensics -- you could boot the undisturbed system under BART, grab a snapshot, do (x), and grab a comparison snapshot agian under BART -- thus avoiding all the other volitle crud that changes between Windows reboots).


~Mike.
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


Current thread: