sk Skill · mukul975
analyzing-windows-amcache-artifacts
Parses the Windows Amcache.hve registry hive with Eric Zimmerman's AmcacheParser and Timeline Explorer to extract evidence of program execution, application installation, and driver loading, including SHA-1 hash correlation with threat intel and timeline reconstruction. Use for Amcache forensics, program execution evidence gathering, or application compatibility cache investigations in DFIR work.
Open on skills.sh ↗read 2026-09-17
- installs 8w
- 0
- 30-day movement
- starts with the next reading
- Related entries
- 1
- Connections
- 0
powershellPythontimeline-analysisDFIReric-zimmermanAmcacheParserprogram-executionwindows-forensicsamcache
- Host repository
- mukul975/Anthropic-Cybersecurity-Skills
- Version
- 1.0.0
- Licence
- Apache-2.0
- Host stars
- 33k
- Host language
- Python