首页| JavaScript| HTML/CSS| Matlab| PHP| Python| Java| C/C++/VC++| C#| ASP| 其他|
购买积分 购买会员 激活码充值

您现在的位置是:虫虫源码 > 其他 > regkeval

regkeval

  • 资源大小:16.32 kB
  • 上传时间:2021-06-30
  • 下载次数:0次
  • 浏览次数:0次
  • 资源积分:1积分
  • 标      签:

资 源 简 介

Added perl program to get all the service triggers from an offline hive: serv-triggers.pl. Service triggers can start and stop services containing malware. You have to run it as: serv-triggers.pl system Regkeval. The idea is to compare as many registry entries as I know that can be used for malware persistence against both a well-known baseline of right and wrong values. Characteristics: Works on offline registry hives. The keys and values to search can be defined using wildcards. It can be used to detect anomalies in computers with similar characteristics and configuration. Resolves any CLSID obtained in the output. Extraction of readable content from binary data. Custom selection of keys to retrieve based on filters. Custom classification of the output. TSV file and colorized html output for easier inspection of results. The
VIP VIP
0.212935s