BigHugger
sk Skill · mukul975

analyzing-windows-amcache-artifacts

Parses the Windows Amcache.hve registry hive with Eric Zimmerman's AmcacheParser and Timeline Explorer to extract evidence of program execution, application installation, and driver loading, including SHA-1 hash correlation with threat intel and timeline reconstruction. Use for Amcache forensics, program execution evidence gathering, or application compatibility cache investigations in DFIR work.

installs 8w
0
30-day movement
starts with the next reading
Related entries
1
Connections
0
powershellPythontimeline-analysisDFIReric-zimmermanAmcacheParserprogram-executionwindows-forensicsamcache
Host repository
mukul975/Anthropic-Cybersecurity-Skills
Version
1.0.0
Licence
Apache-2.0
Host stars
33k
Host language
Python