tag

windows-forensics

5 indexed skills · max 10 per page

skills (5)

analyzing-lnk-file-and-jump-list-artifacts

mukul975/Anthropic-Cybersecurity-Skills · analyzing-lnk-file-and-jump-list-artifacts

0

Analyze Windows LNK shortcut files and Jump List artifacts to establish evidence of file access, program execution, and user activity using LECmd, JLECmd, and manual binary parsing of the Shell Link Binary format.

analyzing-powershell-script-block-logging

mukul975/Anthropic-Cybersecurity-Skills · analyzing-powershell-script-block-logging

0

Parse Windows PowerShell Script Block Logs (Event ID 4104) from EVTX files to detect obfuscated commands, encoded payloads, and living-off-the-land techniques. Uses python-evtx to extract and reconstruct multi-block scripts, applies entropy analysis and pattern matching for Base64-encoded commands, Invoke-Expression abuse, download cradles, and AMSI bypass attempts.

performing-windows-artifact-analysis-with-eric-zimmerman-tools

mukul975/Anthropic-Cybersecurity-Skills · performing-windows-artifact-analysis-with-eric-zimmerman-tools

0

Perform comprehensive Windows forensic artifact analysis using Eric Zimmerman's open-source EZ Tools suite including KAPE, MFTECmd, PECmd, LECmd, JLECmd, and Timeline Explorer for parsing registry hives, prefetch files, event logs, and file system metadata.

hunting-for-registry-run-key-persistence

mukul975/Anthropic-Cybersecurity-Skills · hunting-for-registry-run-key-persistence

0

Detect MITRE ATT&CK T1547.001 registry Run key persistence by analyzing Sysmon Event ID 13 logs and registry queries to identify malicious auto-start entries.

analyzing-windows-amcache-artifacts

mukul975/Anthropic-Cybersecurity-Skills · analyzing-windows-amcache-artifacts

0

Parses and analyzes the Windows Amcache.hve registry hive to extract evidence of program execution, application installation, and driver loading for digital forensics investigations. Uses Eric Zimmerman's AmcacheParser and Timeline Explorer for artifact extraction, SHA-1 hash correlation with threat intel, and timeline reconstruction. Activates for requests involving Amcache forensics, program execution evidence, Windows artifact analysis, or application compatibility cache investigation.