Analyzing Lnk File And Jump List Artifacts

Analyze Windows LNK shortcut files and Jump List artifacts with LECmd, JLECmd, and manual Shell Link Binary Format parsing to establish evidence of file access, program execution, and user activity that persists even after the target file is deleted. Use when investigating Windows user activity, reconstructing file-access or program-execution timelines, or examining recent/frequently-used file evidence in a forensic exam.

gabrielmoreira Updated 17 repo stars

File contents

gabrielmoreira/agent-skills-mirror/tree/main/mirrors/repos/mukul975@Anthropic-Cybersecurity-Skills/skills/analyzing-lnk-file-and-jump-list-artifacts commit faec06183f

Frequently asked questions

npx skillmds@latest add gabrielmoreira/analyzing-lnk-file-and-jump-list-artifacts