Wednesday, March 30, 2011

JL's stuff: Modified Volatility printkey Plugin

Jamie Levy has posted the below update to her modified Volatility printkey Plugin, which includes a "brute-force" option to try to obtain a particular key from all hives. The idea works similar to how hivelist was written to inherit from hivescan; printkey inherits hivelist and can obtain the offsets for all hives if run in brute-force mode. It also retains the previous usage so you can specify an offset.

More details can be obtained from her site here.