Open nrrpinto opened 1 year ago
The recurse_subkeys
function trims value by default (I have to add support for the trim_values
parameter).
Meanwhile, look at the user assist parsing example at https://github.com/mkorman90/regipy/blob/master/regipy/plugins/ntuser/user_assist.py#L80
It is possible to fetch the subkey itself, then use subkey.iter_values(trim_values=False)
to iterate over the values.
From HIVE file NTUSER.DAT, I want to extract the content of Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{GUID}\Count.
All seems good, except the binary data, just 64 bytes are returned; however the complete binary string is 72 bytes.
Example:
This is what should return:![image](https://user-images.githubusercontent.com/29933547/207400426-7e7fb548-a9f1-4faa-80de-9dc0900bbe33.png)
This is what returns: 9200 0000 0000 0000 0000 0000 0000 0000 9976 043d 5c5c a73d 96d2 8c3d 9550 333d 1a1a 1b3c b31a 4a3d 455d c63b b524 c93b d598 393d caff fc3d 0800 0000 5026 b568
The code I am using that writes the retrieved data into a CSV file: