BigHugger
sk Skill · mukul975

analyzing-windows-prefetch-with-python

Parse Windows Prefetch (.pf) files with the windowsprefetch Python library to reconstruct application execution history, run counts, and accessed file/volume lists. Use when investigating renamed or masquerading binaries, verifying program execution timelines, or hunting for suspicious execution patterns in incident response.

installs 8w
0
30-day movement
starts with the next reading
Related entries
1
Connections
0
Pythonmalware-analysisprefetchincident-responseexecution-historywindowsdigital-forensics
Host repository
mukul975/Anthropic-Cybersecurity-Skills
Version
1.0
Licence
Apache-2.0
Host stars
33k
Host language
Python