1
05a Windows
Patrick Neumann edited this page 2024-07-11 16:47:09 +00:00

05a-Windows

01-E01-find-installation-and-version

find-windows-installation-and-version

02a-RAW-remove-hiberfile

See #4 !

02b-RAW-delete-dev-mapping-and-detach-loop-dev

See #4 !

03a-WindowsDir-fred

fred-windows-hives

fred-software-hive

I also think about an alternative (or addition) for some time:

$ regripper -r SOFTWARE -p winver
Launching winver v.20200525
winver v.20200525
(Software) Get Windows version & build info

ProductName               Windows 7 Ultimate  
CSDVersion                Service Pack 1      
BuildLab                  7601.win7sp1_gdr.130828-1532
BuildLabEx                7601.18247.amd64fre.win7sp1_gdr.130828-1532
RegisteredOrganization                        
RegisteredOwner           user                
InstallDate               2013-11-08 11:29:52Z

03b-NTUSER.DAT-fred

fred-user-hive

04-WindowsDir-activate-all-services-in-Vista-and-7

Just right click, fire up and click ok.

05-E01-pwdump

pwdump

06-pwdump-Ophcrack

Ophcrack-tables

Ophcrack

07a-pwdump-hashcat-dictionary

hashcat-dictionary

07b-pwdump-hashcat-brute-force

hashcat-patterns

08-WindowsDir-chntpw

chntpw