|
pyregfi
|
Registry key These represent registry keys (REGFI_NK records) and provide access to their subkeys, values, and other metadata. More...

Public Member Functions | |
| fetch_security (self) | |
| Retrieves the Security properties for this key. | |
| fetch_classname (self) | |
| Retrieves the class name for this key. | |
| get_parent (self) | |
| Retrieves this key's parent key. | |
| is_root (self) | |
| Checks to see if this Key is the root of its Hive. | |
| Public Member Functions inherited from pyregfi._StructureWrapper | |
| __eq__ (self, other) | |
| Test for equality. | |
Static Public Attributes | |
| values = None | |
| A ValueList object representing the list of Values stored on this Key. | |
| subkeys = None | |
| A SubkeyList object representing the list of subkeys stored on this Key. | |
| tuple | name_raw = (b"...") |
| The raw Key name as an uninterpreted bytearray. | |
| str | name = "..." |
| The name of the Key as a (unicode) string. | |
| str | name_encoding = "ascii" |
| The string encoding used to store the Key's name ("ascii" or "utf-16-le"). | |
| int | offset = 0xCAFEBABE |
| The absolute file offset of the Key record's cell in the Hive file. | |
| float | modified = 1300000000.123456 |
| This Key's last modified time represented as the number of seconds since the UNIX epoch in UTC; similar to what time.time() returns. | |
| int | flags = 0x10110001 |
| The NK record's flags field. | |
Registry key These represent registry keys (REGFI_NK records) and provide access to their subkeys, values, and other metadata.
| pyregfi.Key.fetch_classname | ( | self | ) |
Retrieves the class name for this key.
Class names are typically stored as UTF-16LE strings, so these are decoded into proper python (unicode) strings. However, if this fails, a bytearray is instead returned containing the raw buffer stored for the class name.
References pyregfi._StructureWrapper._base, and pyregfi._StructureWrapper._hive.
| pyregfi.Key.get_parent | ( | self | ) |
| pyregfi.Key.is_root | ( | self | ) |
Checks to see if this Key is the root of its Hive.
References pyregfi._StructureWrapper._hive.
Referenced by get_parent().