Analyzing Windows Prefetch With Python

Parse Windows Prefetch (.pf) files with the windowsprefetch Python library to reconstruct application execution history, run counts, and accessed file/volume lists. Use when investigating renamed or masquerading binaries, verifying program execution timelines, or hunting for suspicious execution patterns in incident response.

gabrielmoreira Updated 17 repo stars

File contents

gabrielmoreira/agent-skills-mirror/tree/main/mirrors/repos/mukul975@Anthropic-Cybersecurity-Skills/skills/analyzing-windows-prefetch-with-python commit 851a31401a

Frequently asked questions

npx skillmds@latest add gabrielmoreira/analyzing-windows-prefetch-with-python