Difference between pages "Epoch" and "Registryasxml"

From ForensicsWiki
(Difference between pages)
Jump to: navigation, search
m (New page: The phrase ''Epoch'' is commonly used to describe the time that is represented by the number "0." The following Epochs are known: {| |Applications |Date and Time |Reference |- |Unix File...)
 
 
Line 1: Line 1:
The phrase ''Epoch'' is commonly used to describe the time that is represented by the number "0."
+
Registryasxml is a GUI tool by Stephane Rodriguez that exports and imports Microsoft Registry files with a simple key/value syntax that looks like this:
  
The following Epochs are known:
+
<pre>
 +
<?xml version="1.0" encoding="UTF-8"?>
 +
<registry>
 +
  <k name="HKEY_LOCAL_MACHINE">
 +
  <k name="SYSTEM">
 +
    <k name="Setup">
 +
    <v name="CmdLine" value="setup -newsetup"/>
 +
    <v name="OsLoaderPath" value="\"/>
 +
    <v name="SetupType" value="0x00000000 (0)" type="REG_DWORD"/>
 +
    <v name="SystemPartition" value="\Device\HarddiskVolume1"/>
 +
    <v name="SystemPrefix" value="cf 03 00 00 00 a0 3d e0" type="REG_BINARY"/>
 +
    <v name="SystemSetupInProgress" value="0x00000000 (0)" type="REG_DWORD"/>
 +
    <k name="AllowStart">
 +
      <k name="AFD"/>
 +
      <k name="EventLog"/>
 +
      <k name="PlugPlay"/>
 +
      <k name="ProtectedStorage"/>
 +
      <k name="Rpcss"/>
 +
      <k name="SamSs"/>
 +
      <k name="Seclogon"/>
 +
      <k name="WS2IFSL"/>
 +
    </k>
 +
    </k>
 +
  </k>
 +
  </k>
 +
</registry>
 +
</pre>
  
{|
+
 
|Applications
+
== See Also ==
|Date and Time
+
* [[Windows Registry]]
|Reference
+
 
|-
+
== External Links ==
|Unix File Systems
+
* http://www.codeproject.com/KB/system/registryasxml.aspx
|January 1, 1970 GMT
+
|-
+
|Apple File Systems
+
|January 1, 1904 GMT
+
|http://developer.apple.com/technotes/tn/tn1150.html#HFSPlusDates
+
|}
+

Revision as of 00:30, 23 July 2012

Registryasxml is a GUI tool by Stephane Rodriguez that exports and imports Microsoft Registry files with a simple key/value syntax that looks like this:

<?xml version="1.0" encoding="UTF-8"?>
 <registry>
  <k name="HKEY_LOCAL_MACHINE">
   <k name="SYSTEM">
    <k name="Setup">
     <v name="CmdLine" value="setup -newsetup"/>
     <v name="OsLoaderPath" value="\"/>
     <v name="SetupType" value="0x00000000 (0)" type="REG_DWORD"/>
     <v name="SystemPartition" value="\Device\HarddiskVolume1"/>
     <v name="SystemPrefix" value="cf 03 00 00 00 a0 3d e0" type="REG_BINARY"/>
     <v name="SystemSetupInProgress" value="0x00000000 (0)" type="REG_DWORD"/>
     <k name="AllowStart">
      <k name="AFD"/>
      <k name="EventLog"/>
      <k name="PlugPlay"/>
      <k name="ProtectedStorage"/>
      <k name="Rpcss"/>
      <k name="SamSs"/>
      <k name="Seclogon"/>
      <k name="WS2IFSL"/>
     </k>
    </k>
   </k>
  </k>
 </registry>


See Also

External Links