Performing Windows Artifact Analysis With Eric Zimmerman Tools

Performs comprehensive Windows forensic artifact analysis using Eric Zimmerman's open-source EZ Tools suite (KAPE, MFTECmd, PECmd, LECmd, JLECmd, Timeline Explorer) to parse registry hives, prefetch files, event logs, and file system metadata. Use during DFIR investigations that need a timeline of program execution, file access, and persistence built from Windows artifacts.

gabrielmoreira Updated 17 repo stars

File contents

gabrielmoreira/agent-skills-mirror/tree/main/mirrors/repos/mukul975@Anthropic-Cybersecurity-Skills/skills/performing-windows-artifact-analysis-with-eric-zimmerman-tools commit 17e19d8d7f

Frequently asked questions

npx skillmds@latest add gabrielmoreira/performing-windows-artifact-analysis-with-eric-zimmerman-too