BigHugger
sk Skill · mukul975

analyzing-lnk-file-and-jump-list-artifacts

Analyze Windows LNK shortcut files and Jump List artifacts with LECmd, JLECmd, and manual Shell Link Binary Format parsing to establish evidence of file access, program execution, and user activity that persists even after the target file is deleted. Use when investigating Windows user activity, reconstructing file-access or program-execution timelines, or examining recent/frequently-used file evidence in a forensic…

installs 8w
0
30-day movement
starts with the next reading
Related entries
1
Connections
0
pythonPythonprogram-executionshell-linkfile-accessuser-activitywindows-forensicsjlecmdrecent-filesjump-listspowershelllecmdlnk-files
Host repository
mukul975/Anthropic-Cybersecurity-Skills
Version
1.0
Licence
Apache-2.0
Host stars
33k
Host language
Python