Skip to main content

parse_pair

Function parse_pair 

Source
pub fn parse_pair(
    hku_hive: &Hive<Cursor<Vec<u8>>>,
    hkcr_hive: &Hive<Cursor<Vec<u8>>>,
) -> Vec<ComHijackInfo>
Expand description

Parse COM hijacking candidates from a pair of hives.

hku_hive: NTUSER.DAT — contains Software\Classes\CLSID user overrides. hkcr_hive: SOFTWARE or USRCLASS.DAT — contains the system-wide CLSID registrations.