I am writing an Autopsy Data Ingest plug-in that calls the command line version of RegRipper (rip.exe) using its bam plugin module. Unfortunately, when Autopsy launches rip, rip does not recognize my Registry file as a SYSTEM hive.
Rip has a -g switch that tells it to guess the type of registry file. In testing, I discovered that in Autopsy:
rip “SYSTEM.reg” -g
returns “unknown = 1”.
However, the same rip command line run in a Windows command shell returns “system = 1”.
Have you ever heard of anything like this? I would appreciate any insight you share.