Windows Registry Forensics

Conduct expert-level incident response analysis of the Windows Registry structure (SAM, SYSTEM, SOFTWARE, NTUSER.DAT). Extract pivotal artifacts detailing threat actor execution (ShimCache, Amcache, UserAssist), persistence mechanisms (RunKeys), and lateral movement activities (RDP connections, mapped drives).

ShulkwiSEC deae05f 3 files · 18.2 KB Updated 21 repo stars

File contents

ShulkwiSEC/bb-huge/tree/main/skills/curated/windows-registry-forensics commit deae05fb6c

Frequently asked questions

npx skillmds add shulkwisec/windows-registry-forensics