Monday, December 29, 2014

Registry Explorer - Feature update - Date Time Filter

It's still pre-beta. I haven't gotten to the point where I've untangled it from my other project.

I have added the Date Time restriction feature. This allows an examiner to display all the named registry keys with a last modified  timestamp between a given start and stop date/time.

And a quick video of the feature in action.
  • In the video I selectively target the "7-zip" named key - last modified Sept 27, 2012. 
  • Set a start and stop data around the last modified for the key.
    • Start: Sept 26, 2012
    • Stop: Sept 28, 2012
  • The returned results are default sorted by date time. In order to find my target I sorted the Name column.
  • Double click the "Name" column header to sort, then hit the first letter of the field of interest to jump to it. 
  • The selected entry populates the right side table and property tabs.

I may add the following additional timestamp related features:

  • Time normalization to timezone offset.
  • Default start and stop date time being set to the last selected Named Key.

No comments:

Post a Comment