Performing Windows Artifact Analysis With Eric Zimmerman Tools

mukul975/performing-windows-artifact-analysis-with-eric-zimmerman-too · Agent Skill (multi-file)

by mukul975 · bundle

Published · Last updated


Parse and analyze Windows forensic artifacts including MFT, registry hives, prefetch files, event logs, LNK files, and jump lists using Eric Zimmerman's EZ Tools suite and KAPE.

SKILL.md

Files

This skill is a package of 8 files. Install with the command above, or download the folder.

Related

  1. Extracting Windows Event Logs Artifacts · mukul975 bundle
    Extract, parse, and analyze Windows Event Logs (EVTX) using Chainsaw, Hayabusa, and EvtxECmd to detect lateral movement, persistence, and privilege escalation.
    24.6k
    repo stars
  2. Analyzing Prefetch Files For Execution History · mukul975 bundle
    Parse Windows Prefetch files to determine program execution history including run counts, timestamps, and referenced files for forensic investigation.
    24.6k
    repo stars
  3. Analyzing Lnk File And Jump List Artifacts · mukul975 bundle
    Analyze Windows LNK shortcut files and Jump List artifacts to establish evidence of file access, program execution, and user activity using LECmd, JLECmd, and manual binary parsing.
    24.6k
    repo stars
  4. Parsing Artifacts With Eric Zimmerman Tools · mukul975 bundle
    Parse Windows forensic artifacts including registry, prefetch, shellbags, MFT, and event logs using Eric Zimmerman's tools and analyze results in Timeline Explorer.
    24.6k
    repo stars
  5. Analyzing Windows Shellbag Artifacts · mukul975 bundle
    Analyze Windows Shellbag registry artifacts to reconstruct folder browsing activity, detect access to removable media and network shares, and establish user interaction with directories even after deletion using SBECmd and ShellBags Explorer.
    24.6k
    repo stars
  6. Analyzing Usb Device Connection History · mukul975 bundle
    Investigate USB device connection history from Windows registry, event logs, and setupapi logs to track removable media usage and potential data exfiltration.
    24.6k
    repo stars

Frequently asked questions

How do I install the Performing Windows Artifact Analysis With Eric Zimmerman Tools skill?

Run npx skillmds add mukul975/performing-windows-artifact-analysis-with-eric-zimmerman-too in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.

What does the Performing Windows Artifact Analysis With Eric Zimmerman Tools skill do?

Parse and analyze Windows forensic artifacts including MFT, registry hives, prefetch files, event logs, LNK files, and jump lists using Eric Zimmerman's EZ Tools suite and KAPE. It is listed under Security, Coding & Dev Tools, Data & Analytics, Data Analysis, Incident Response on SkillMD.

Is Performing Windows Artifact Analysis With Eric Zimmerman Tools safe to use?

SkillMD's automated safety review verdict for this skill is CAUTION. Independent scanners report: SkillSpector: PASS, Skill Scanner: PASS. Capability flags: executes scripts, makes network calls. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.

Which AI agents work with Performing Windows Artifact Analysis With Eric Zimmerman Tools?

This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.

Is Performing Windows Artifact Analysis With Eric Zimmerman Tools free to use?

Yes. Installing skills from SkillMD is free. This skill is licensed under Apache-2.

Who published Performing Windows Artifact Analysis With Eric Zimmerman Tools?

mukul975 (@mukul975) published this skill. Their other Agent Skills are listed on their SkillMD profile.