Closed mischw closed 4 days ago
@mischw
In rla.exe
you need to include --ca
and/or --cn
in your command depending on your use case.
rla.exe -d [registry directory] --ca False --cn False --out [output directory]
This will export only the ntuser/usrclass hives that need to be replayed (i.e., dirty) into the specified directory.
rla.exe -d [registry directory] --cn False --out [output directory]
This will export all the ntuser/usrclass hives regardless of if they need to be replayed into the specified directory.
rla.exe -d [single registry directory] --cn False --nop True [output directory]
rla.exe -d E:\C\Users\johndoe --cn False --nop True C:\output"
This will export only the ntuser/usrclass hive specified but will not recreate the path where the hives were located.
You can also run rla.exe -d C:\Users --out C:\out
to find out which user hives are dirty too.
I hope that helps you out!
Sometimes it just happens. Could be how you pulled the logs, could be a bug. I haven't seen a consistent problem for me to fix tho. Use the nologs switch on the tools and it generally can open things, without the logs of course
@bmmojo Thanks for the suggestion. Unfortunately even with the ca/cn flags I get the error message and the hives are not copied.
@EricZimmerman But how come RECmd is able to open and replay these log files? I assumed RECmd is based on / or shares code with rla. Is that not the case?
If recmd works so should rla
On Tue, Jul 30, 2024, 4:04 PM Michael @.***> wrote:
@bmmojo https://github.com/bmmojo Thanks for the suggestion. Unfortunately even with the ca/cn flags I get the error message and the hives are not copied.
@EricZimmerman https://github.com/EricZimmerman But how come RECmd is able to open an replay these log files? I assumed RECmd is based on / or shares code with rla. Is that not the case?
— Reply to this email directly, view it on GitHub https://github.com/EricZimmerman/RECmd/issues/59#issuecomment-2259115638, or unsubscribe https://github.com/notifications/unsubscribe-auth/ABARKJTA747OBRI4WVB2KFLZO7WTZAVCNFSM6AAAAABLR2E25KVHI2DSMVQWIX3LMV43OSLTON2WKQ3PNVWWK3TUHMZDENJZGEYTKNRTHA . You are receiving this because you were mentioned.Message ID: @.***>
Sorry, I expressed myself incorrectly. According to the logs both, rla and recmd, are actually able to replay the logs fine. The error with rla seems to be after that when the updated hive should be written to file, just before the Saving updated hive to ...
which is never reached with rla.
Sharing the hive and corresponding logs goes a long way to fixing this stuff
In my initial post I provided
For your convenience, here is the extracted hive too. I don't see what else I could possibly provide.
this should be fixed. was an issue finding the name of the profile, etc. please test rla again
I can confirm it does work now. Thanks!
RECmd version 2.0.0.0
rla version 2.0.0.0
Describe the bug I am trying to run
rla.exe
on the NTUSER.DAT of the Administrator account. While processing withrla.exe
I get an errorSystem.IndexOutOfRangeException
. I also tried to runRECmd.exe
which does not produce such message. Here are the logs:RECmd log:
To Reproduce I took the NTUSER.DAT from the DC01 Image from here if you want to reproduce.
Expected behavior I wanted
rla.exe
to write a clean NTUSER.DAT to..\out\
for further processing.