regrippy
Framework for reading and extracting useful forensics data from Windows registry hives.
Platforms: Linux · Last verified September 6, 2026
Framework for reading and extracting useful forensics data from Windows registry hives.
Only use this tool against systems you own or are explicitly authorized to test — see the disclaimer.
Getting started
Install on BlackArch with `pacman -S regrippy` (or add the BlackArch repository to an existing Arch Linux install). See the official BlackArch tool listing and upstream homepage linked above for details.
