Analyzing Windows Amcache Artifacts
Extract execution evidence from Amcache.hve including application paths, SHA-1 hashes, timestamps, and publisher metadata for DFIR investigations.
Parse and analyze Windows Amcache.hve registry hive to extract program execution evidence, file metadata, SHA-1 hashes, and device connection history for digital forensics and incident response investigations.
npx skillmds@latest add autohandai-community-skills/analyzing-windows-amcache-artifacts Extract execution evidence from Amcache.hve including application paths, SHA-1 hashes, timestamps, and publisher metadata for DFIR investigations.
autohandai/community-skills/tree/main/analyzing-windows-amcache-artifacts commit 9c353b56b3