volatility3.plugins.windows.registry package
Windows registry plugins.
NOTE: This file is important for core plugins to run (which certain components such as the windows registry layers) are dependent upon, please DO NOT alter or remove this file unless you know the consequences of doing so.
The framework is configured this way to allow plugin developers/users to override any plugin functionality whether existing or new.
When overriding the plugins directory, you must include a file like this in any subdirectories that may be necessary.
Submodules
- volatility3.plugins.windows.registry.amcache module
AmcacheAmcache.build_configuration()Amcache.configAmcache.config_pathAmcache.contextAmcache.generate_timeline()Amcache.get_amcache_hive()Amcache.get_requirements()Amcache.make_subconfig()Amcache.openAmcache.parse_driver_binary_key()Amcache.parse_file_key()Amcache.parse_inventory_app_file_key()Amcache.parse_inventory_app_key()Amcache.parse_programs_key()Amcache.run()Amcache.set_open_method()Amcache.unsatisfied()Amcache.version
AmcacheEntryTypeAmcacheEntryType.DriverAmcacheEntryType.FileAmcacheEntryType.ProgramAmcacheEntryType.as_integer_ratio()AmcacheEntryType.bit_count()AmcacheEntryType.bit_length()AmcacheEntryType.conjugate()AmcacheEntryType.denominatorAmcacheEntryType.from_bytes()AmcacheEntryType.imagAmcacheEntryType.numeratorAmcacheEntryType.realAmcacheEntryType.to_bytes()
Win10DriverBinaryValNameWin10InvAppFileValNameWin10InvAppValNameWin8FileValNameWin8FileValName.CompanyWin8FileValName.CompileTimeWin8FileValName.CreateTimeWin8FileValName.LastModTimeWin8FileValName.LastModTime2Win8FileValName.PEHeaderChecksumWin8FileValName.PathWin8FileValName.ProductWin8FileValName.ProgramIDWin8FileValName.SHA1HashWin8FileValName.SizeWin8FileValName.SizeOfImageWin8FileValName.Version
Win8ProgramValName
- volatility3.plugins.windows.registry.cachedump module
CachedumpCachedump.build_configuration()Cachedump.configCachedump.config_pathCachedump.contextCachedump.decrypt_hash()Cachedump.get_nlkm()Cachedump.get_requirements()Cachedump.make_subconfig()Cachedump.openCachedump.parse_cache_entry()Cachedump.parse_decrypted_cache()Cachedump.run()Cachedump.set_open_method()Cachedump.unsatisfied()Cachedump.version
- volatility3.plugins.windows.registry.getcellroutine module
GetCellRoutineGetCellRoutine.build_configuration()GetCellRoutine.configGetCellRoutine.config_pathGetCellRoutine.contextGetCellRoutine.get_requirements()GetCellRoutine.make_subconfig()GetCellRoutine.openGetCellRoutine.run()GetCellRoutine.set_open_method()GetCellRoutine.unsatisfied()GetCellRoutine.version
- volatility3.plugins.windows.registry.hashdump module
HashdumpHashdump.almpasswordHashdump.antpasswordHashdump.anumHashdump.aqwertyHashdump.bootkey_perm_tableHashdump.build_configuration()Hashdump.configHashdump.config_pathHashdump.contextHashdump.decrypt_single_hash()Hashdump.decrypt_single_salted_hash()Hashdump.empty_lmHashdump.empty_ntHashdump.get_bootkey()Hashdump.get_hbootkey()Hashdump.get_hive_key()Hashdump.get_requirements()Hashdump.get_user_hashes()Hashdump.get_user_keys()Hashdump.get_user_name()Hashdump.lmkeyHashdump.make_subconfig()Hashdump.odd_parityHashdump.openHashdump.run()Hashdump.set_open_method()Hashdump.sid_to_key()Hashdump.sidbytes_to_key()Hashdump.unsatisfied()Hashdump.version
- volatility3.plugins.windows.registry.hivelist module
- volatility3.plugins.windows.registry.hivescan module
- volatility3.plugins.windows.registry.lsadump module
LsadumpLsadump.build_configuration()Lsadump.configLsadump.config_pathLsadump.contextLsadump.decrypt_aes()Lsadump.decrypt_secret()Lsadump.get_lsa_key()Lsadump.get_requirements()Lsadump.get_secret_by_name()Lsadump.make_subconfig()Lsadump.openLsadump.run()Lsadump.set_open_method()Lsadump.unsatisfied()Lsadump.version
- volatility3.plugins.windows.registry.printkey module
- volatility3.plugins.windows.registry.scheduled_tasks module
ActionSetActionTypeDynamicInfoJobBucketMonthsOptionalSettingsOptionalSettings.DeadlineOptionalSettings.DeleteExpiredTaskAfterOptionalSettings.ExclusiveOptionalSettings.ExecutionTimeLimitSecondsOptionalSettings.IdleDurationSecondsOptionalSettings.NetworkIdOptionalSettings.PeriodicityOptionalSettings.PriorityOptionalSettings.PrivilegesOptionalSettings.RestartOnFailureDelayOptionalSettings.RestartOnFailureRetriesOptionalSettings.idleWaitTimeoutSeconds
PrivilegesPrivileges.SeAssignPrimaryTokenPrivilegePrivileges.SeAuditPrivilegePrivileges.SeBackupPrivilegePrivileges.SeChangeNotifyPrivilegePrivileges.SeCreateGlobalPrivilegePrivileges.SeCreatePagefilePrivilegePrivileges.SeCreatePermanentPrivilegePrivileges.SeCreateSymbolicLinkPrivilegePrivileges.SeCreateTokenPrivilegePrivileges.SeDebugPrivilegePrivileges.SeDelegateSessionUserImpersonatePrivilegePrivileges.SeEnableDelegationPrivilegePrivileges.SeImpersonatePrivilegePrivileges.SeIncreaseBasePriorityPrivilegePrivileges.SeIncreaseQuotaPrivilegePrivileges.SeIncreaseWorkingSetPrivilegePrivileges.SeLoadDriverPrivilegePrivileges.SeLockMemoryPrivilegePrivileges.SeMachineAccountPrivilegePrivileges.SeManageVolumePrivilegePrivileges.SeProfileSingleProcessPrivilegePrivileges.SeRelabelPrivilegePrivileges.SeRemoteShutdownPrivilegePrivileges.SeRestorePrivilegePrivileges.SeSecurityPrivilegePrivileges.SeShutdownPrivilegePrivileges.SeSyncAgentPrivilegePrivileges.SeSystemEnvironmentPrivilegePrivileges.SeSystemProfilePrivilegePrivileges.SeSystemtimePrivilegePrivileges.SeTakeOwnershipPrivilegePrivileges.SeTcbPrivilegePrivileges.SeTimeZonePrivilegePrivileges.SeTrustedCredManAccessPrivilegePrivileges.SeUndockPrivilege
ScheduledTasksScheduledTasks.build_configuration()ScheduledTasks.configScheduledTasks.config_pathScheduledTasks.contextScheduledTasks.generate_timeline()ScheduledTasks.get_requirements()ScheduledTasks.get_software_hive()ScheduledTasks.make_subconfig()ScheduledTasks.openScheduledTasks.parse_actions_value()ScheduledTasks.parse_dynamic_info_value()ScheduledTasks.parse_triggers_value()ScheduledTasks.run()ScheduledTasks.set_open_method()ScheduledTasks.unsatisfied()ScheduledTasks.version
SessionStateSidTypeTaskActionTaskSchedulerTimePeriodTaskTriggerTimeModeTriggerSetTriggerTypeUserInfoWeekdaydecode_sid()
- volatility3.plugins.windows.registry.userassist module
UserAssistUserAssist.build_configuration()UserAssist.configUserAssist.config_pathUserAssist.contextUserAssist.generate_timeline()UserAssist.get_requirements()UserAssist.list_userassist()UserAssist.make_subconfig()UserAssist.openUserAssist.parse_userassist_data()UserAssist.run()UserAssist.set_open_method()UserAssist.unsatisfied()UserAssist.version