Registry Hive Parser

Paste a hex or Base64-encoded Windows registry hive and inspect the regf header, root keys, selected paths, or common Run/RunOnce autostart locations. Runs locally in your browser; no hive upload.

Try:
Result

About this tool

Registry Hive Parser is a local DFIR helper for offline Windows registry hives such as NTUSER.DAT, SYSTEM, SOFTWARE, SAM, SECURITY, USRCLASS.DAT, and Amcache hives. Encode the hive as hex or Base64, paste it into the form, then choose a summary, a specific key path, or an autostart RunKeys sweep.

The summary mode validates the regf signature, parses the base-block metadata, recomputes the header checksum, flags dirty sequence numbers and truncation, and lists root subkeys/values when structured traversal succeeds. Path mode browses a backslash-separated key relative to the hive root, so use Software\\Microsoft\\Windows\\CurrentVersion\\Run for an NTUSER.DAT hive rather than adding HKCU. RunKeys mode probes common per-user, machine-wide, policy, Winlogon, BootExecute, and 32-bit-view autostart locations used during incident response.

Worked example

To inspect an NTUSER Run key from the command line after installing the CLI:

gizza tool registry-hive-parser --data "$(xxd -p -c 256 NTUSER.DAT)" --mode path --path "Software\\Microsoft\\Windows\\CurrentVersion\\Run" --max-entries 25

For a quick browser smoke test, paste 504b0304140000000800 with summary mode. The tool should reject it as a ZIP header, not a registry hive. Real hive bytes begin with ASCII regf (72 65 67 66 in hex) and must include the 4096-byte base block.

Limits and edge cases

FAQ

Do I paste a file path or the hive bytes?

Paste the hive bytes encoded as hex or Base64. Browser and chat blocks cannot read your local disk path directly, so encode the file first, for example with xxd -p NTUSER.DAT or base64 NTUSER.DAT.

Should my path include HKCU or HKLM?

No. An offline hive starts at its own root. For NTUSER.DAT, enter a path such as Software\\Microsoft\\Windows\\CurrentVersion\\Run; for a SOFTWARE hive, enter Microsoft\\Windows\\CurrentVersion\\Run.

Can it recover deleted keys or replay registry logs?

No. It reports live keys/values when the hive tree parses and can carve key names from damaged hives as a fallback. It does not replay transaction logs or reconstruct deleted-cell timelines.

Why does RunKeys mode say a location is missing?

RunKeys mode checks known paths across NTUSER.DAT, SOFTWARE, and SYSTEM-style hives. A missing path usually means the loaded hive family does not contain that location or the software has no values configured there.

Developer & Automation Access

Run it from the terminal

Same engine as this page, headless — via the gizza CLI:

gizza tool registry-hive-parser "Paste hex bytes starting with 72 65 67 66 ... (ASCII 'regf'), or choose Base64 below"

New to the CLI? Get gizza →

Open it by URL

Pre-fill and auto-run this tool with query parameters — the names match the API/CLI:

https://gizza.ai/tools/registry-hive-parser/?data=Paste%20hex%20bytes%20starting%20with%2072%2065%2067%2066%20...%20%28ASCII%20%27regf%27%29%2C%20or%20choose%20Base64%20below&input_encoding=hex&mode=summary&path=Software%5CMicrosoft%5CWindows%5CCurrentVersion%5CRun&max_entries=50

Machine-readable descriptor: tool.json — title + parameters JSON Schema for agents.