Service interruption on Monday 11 July from 12:30 to 13:00: all the sites of the CCSD (HAL, Epiciences, SciencesConf, AureHAL) will be inaccessible (network hardware connection).
Skip to Main content Skip to Navigation
Conference papers

XML Conversion of the Windows Registry for Forensic Processing and Distribution

Abstract : The Windows Registry often contains key data that help determine the activities performed on a computer. While some forensic tools format Registry data for common questions that are required to be answered in digital investigations, their output is geared for standalone use, not for indexable content.This paper describes RegXML, an XML syntax designed to represent Windows Registry hive files. RegXML captures the logical structure of a hive and notes the locations of found data within hive files. The paper also describes a Python library designed to be used with RegXML and the results obtained upon applying the library to analyze two forensic corpora. Experimental results are presented based on hundreds of disk images, thousands of hive files and tens of millions of Registry cells.
Document type :
Conference papers
Complete list of metadata
Contributor : Hal Ifip Connect in order to contact the contributor
Submitted on : Tuesday, May 16, 2017 - 5:10:09 PM
Last modification on : Thursday, March 5, 2020 - 4:46:27 PM
Long-term archiving on: : Friday, August 18, 2017 - 12:52:42 AM


Files produced by the author(s)


Distributed under a Creative Commons Attribution 4.0 International License



Alex Nelson. XML Conversion of the Windows Registry for Forensic Processing and Distribution. 8th International Conference on Digital Forensics (DF), Jan 2012, Pretoria, South Africa. pp.51-65, ⟨10.1007/978-3-642-33962-2_4⟩. ⟨hal-01523700⟩



Record views


Files downloads