BigHugger
sk Skill · mukul975

parsing-artifacts-with-eric-zimmerman-tools

Parse Windows forensic artifacts—$MFT/$J (MFTECmd), Prefetch (PECmd), registry hives (RECmd), shellbags, and Amcache—into normalized CSV/JSON with Eric Zimmerman's EZ Tools, then load results into Timeline Explorer for analysis. Use during DFIR/incident-response investigations, after triage collection (e.g. with KAPE), to establish program execution, file/folder access, and persistence evidence from acquired…

installs 8w
0
30-day movement
starts with the next reading
Related entries
1
Connections
0
powershellPythondfirmftshellbagsprefetchartifact-parsingregistry-forensicseric-zimmermancmddigital-forensics
Host repository
mukul975/Anthropic-Cybersecurity-Skills
Version
1.0
Licence
Apache-2.0
Host stars
33k
Host language
Python