BigHugger
sk Skill · mukul975

analyzing-prefetch-files-for-execution-history

Parse Windows Prefetch files (versions 17, 23, 26, 30) with tools like PECmd, WinPrefetchView, or python-prefetch to determine program execution history, including run counts, execution timestamps, and referenced files/DLLs. Use when building a timeline of program execution on a Windows system, confirming whether a suspicious binary ran, or correlating execution evidence with other forensic artifacts during an…

installs 8w
0
30-day movement
starts with the next reading
Related entries
1
Connections
0
bashevidence-collectiontimeline-analysisexecution-historywindows-artifactsprefetchPythonforensics
Host repository
mukul975/Anthropic-Cybersecurity-Skills
Version
1.0
Licence
Apache-2.0
Host stars
33k
Host language
Python