pkg.soopen package index

brew / rank 6825

Install regipy with Homebrew

Offline registry hive parsing tool. Version 6.3.0 via Homebrew; verified 2026-07-19.

install

Additional install commands

macOS

Homebrewverified · 100%
brew install regipy

local Homebrew formula metadata

overview

Package summary

Offline registry hive parsing tool

Commands and aliases

  • regipy-diff
  • regipy-dump
  • regipy-parse-header
  • regipy-plugins-list
  • regipy-plugins-run
  • regipy-process-transaction-logs

history

Project history and usage

regipy is a Python library and command suite for offline Windows Registry hive parsing and forensic artifact extraction.

Project history

regipy was created as a Python toolkit for offline parsing of Windows Registry hive files. It grew beyond basic parsing to include transaction-log recovery, hive comparison, and a plugin framework for extracting forensic artifacts.

Adoption history

regipy is packaged as both a Python library and a collection of command-line programs. Its plugin system and dedicated tools for hive dumping, differencing, header parsing, and transaction-log processing support repeatable forensic workflows.

How it is used

Users can parse hive metadata, dump hive contents, compare hives, enumerate or run forensic plugins, and process transaction logs through the supplied regipy-* executables or the Python API.

Why package nerds care

The project gives Unix and macOS users a scriptable, offline way to examine Windows Registry artifacts without using the Windows Registry APIs. That combination is particularly useful for cross-platform incident-response and forensic pipelines.

Timeline

  • 5.0.0: The project reported 52 forensic plugins and introduced validation cases for plugins
  • 6.2.0: Additional plugins were released
  • 6.2.1: The project added an MCP server and maintenance updates

Related projects

  • Windows Registry hive format
  • digital-forensics and incident-response tooling
  • Python

security posture

Risk level: green

narrow executable package without higher-risk signals.

Risk classifier

green risk · low confidence · appliance

Why

  • narrow executable package without higher-risk signals

Signals

  • metadata:no-higher-risk-signals

Install behavior

  • No Homebrew post-install hook is recorded in formula metadata.
  • Homebrew bottle metadata is available for 1 platform targets.
  • Installs with 1 runtime dependencies.

Recommended review

Before unattended agent use, check whether the tool reads plaintext credentials, writes remote state, publishes artifacts, or shells out to plugins.

executables

Installed executables

CommandKindExposureNote
regipy-diffcliglobal executable
regipy-dumpcliglobal executable
regipy-parse-headercliglobal executable
regipy-plugins-listcliglobal executable
regipy-plugins-runcliglobal executable
regipy-process-transaction-logscliglobal executable

freshness

Version and freshness

These signals separate page generation age, package-manager activity, and upstream release comparison. Version lag is warned only when an evidence URL and comparable versions are present.

page generated2026-09-19
manager version6.3.0
manager updated2026-07-19
local dataok
upstreamnot checked
latest detectednot detected

https://github.com/mkorman90/regipy

install metadata

Package metadata

Package keybrew:regipy
Version6.3.0
Package managerHomebrew
Package manager pagehttps://formulae.brew.sh/formula/regipy
Homepagehttps://github.com/mkorman90/regipy
Repositoryhttps://github.com/mkorman90/regipy
LicenseMIT
Source archivehttps://files.pythonhosted.org/packages/25/a2/9427da67acc61b39cda35be4cc788a9c99e27622b514e1c6ba87a90adb84/regipy-6.3.0.tar.gz
Last updated2026-07-19T15:23:45Z
Pulseupdated
Dependenciespython@3.14
Bottleavailable (on all)
Homebrew post-installnot defined
Servicenone declared

registry facts

Source database details

Source DatabaseHomebrew formula API
Taphomebrew/core
Full Nameregipy
Version Scheme0
Revision0
Head VersionHEAD
Bottle Stable Root URLhttps://ghcr.io/v2/homebrew/core
Deprecatedno
Disabledno
Keg Onlyno
URL Keys
  • head
  • stable

source trail

Generated from repository data

This page is generated by av-web from the private package SQLite artifact built by scripts/generate-pkg-sqlite.py.

Used sources

  • Geiger risk classifier
  • cross-ecosystem install command graph
  • curated package history
  • package relationship graph
  • package version freshness
  • package-page enrichment
  • pkg.so package database
  • pkgdb category and tag curation