Results for “registry-analysis”
21 skillsAnalyzing Usb Device Connection History
Investigate USB device connection history from Windows registry, event logs, and setupapi logs to track removable media usage and potential data exfiltration.
24.6k · bundle
Performing Malware Ioc Extraction
Analyze malicious software to extract actionable indicators of compromise including file hashes, network indicators, registry modifications, and embedded strings, formatted as STIX 2.1 indicators.
24.6k · bundle
More results
Analyzing Windows Registry For Artifacts
Extract and analyze Windows Registry hives to uncover user activity, installed software, autostart entries, and evidence of system compromise.
24.6k · bundle
Analyzing Windows Shellbag Artifacts
Analyze Windows Shellbag registry artifacts to reconstruct folder browsing activity, detect access to removable media and network shares, and establish user interaction with directories even after deletion using SBECmd and ShellBags Explorer.
24.6k · bundle
Hunting For Registry Run Key Persistence
Detect MITRE ATT&CK T1547.001 registry Run key persistence by analyzing Sysmon Event ID 13 logs and registry queries to identify malicious auto-start entries.
24.6k · bundle
Hunting For Registry Persistence Mechanisms
Hunt for registry-based persistence mechanisms including Run keys, Winlogon modifications, IFEO injection, and COM hijacking in Windows environments.
24.6k · bundle
Review
Analyze auto-memory for promotion candidates, stale entries, consolidation opportunities, and health metrics.
0
Performing Malware Persistence Investigation
Systematically investigate all persistence mechanisms on Windows and Linux systems to identify how malware survives reboots and maintains access.
24.6k · bundle
Analyzing Malware Persistence With Autoruns
Identify and analyze malware persistence mechanisms on Windows systems using Sysinternals Autoruns, covering registry keys, scheduled tasks, services, drivers, and startup locations.
24.6k · bundle
Skill Registry
Sincroniza el registro central de skills con AGENTS.md y registry/AGENT_REGISTRY.md, detectando skills huérfanas o faltantes y auditando el ecosistema.
0
Extracting Memory Artifacts With Rekall
Analyze Windows memory dumps for signs of compromise using the Rekall memory forensics framework, including process injection, hidden processes, and rootkit detection.
24.6k · bundle
Example Skill
Example skill demonstrating the registry structure and format
3
Ripple
Analyzing pre-change impact across vertical (dependency chains, files) and horizontal (pattern consistency, naming) dimensions. Use to estimate blast radius before a refactor. No code.
65 · bundle
Churn Analysis
Turn churned and downgraded accounts into an early-warning system. Reads the customers who left or shrank, extracts the themes behind why, builds a warning checklist from the real causes, then reads your active book and flags which accounts look like the ones that just churned. Built for B2B retention teams, customizable to your CRM and your customer data. Trigger on "why do customers churn", "what do churned accounts have in common", "build me a churn early-warning list", "which accounts are at risk of churning", "who looks like a recent churner", or any retention post-mortem.
0 · bundle
Conducting Memory Forensics With Volatility
Analyze RAM dumps with Volatility 3 to detect malware, process injection, network connections, and credential theft during incident response.
24.6k · bundle
Review
Analyze auto-memory for promotion candidates, stale entries, consolidation opportunities, and health metrics.
3
Churn Detector
Weekly churn risk detection across active client accounts. Scans for signals like decreased engagement, missed meetings, delayed payments, and competitor mentions. Scores risk 1-10 and outputs prioritized alert list.
2 · bundle
Review
Analyze auto-memory for promotion candidates, stale entries, consolidation opportunities, and health metrics. Use when the user runs /si:review or asks what has been learned and what should be promoted or pruned.
11
Refactoring Analyst
Refactoring Analyst
2 · bundle
Refactoring
Splits, merges, moves, or deletes code while preserving behavior, tests, contracts, and boundaries, with characterization evidence and reversible steps.
4 · bundle
Performing Windows Artifact Analysis With Eric Zimmerman Too
Parse and analyze Windows forensic artifacts including MFT, registry hives, prefetch files, event logs, LNK files, and jump lists using Eric Zimmerman's EZ Tools suite and KAPE.
24.6k · bundle