Analyzing Windows Lnk Files For Artifacts

Parse Windows LNK shortcut files to extract target paths, MAC timestamps, volume serial numbers, and machine identifiers for forensic timeline reconstruction. Use when investigating recently-accessed files, tracking removable media or network paths referenced by shortcuts, or building a DFIR timeline from LNK artifacts.

gabrielmoreira Updated 17 repo stars

File contents

gabrielmoreira/agent-skills-mirror/tree/main/mirrors/repos/mukul975@Anthropic-Cybersecurity-Skills/skills/analyzing-windows-lnk-files-for-artifacts commit b2b372b6cd

Frequently asked questions

npx skillmds@latest add gabrielmoreira/analyzing-windows-lnk-files-for-artifacts