Skip to main content

investigating-windows-endpoints

Investigate a live or triaged Windows host for intrusion evidence using disk and registry artifacts — MFT/$UsnJrnl, registry hives, AmCache/ShimCache, Prefetch, LNK/JumpLists, ShellBags, and event logs — parsed with the Eric Zimmerman suite and consolidated into a timeline. Use when a Windows endpoint is suspect and you need execution, persistence, and access evidence from on-disk artifacts. Preserve order of volatility first; a running command is a write to the evidence.

الانتقال إلى التثبيت

معلومات المصدر

المستودع
EvilFreelancer/secs
آخر نشاط في المصدر
٨ أغسطس ٢٠٢٦ في ٢٠:٥٦
لغة SKILL.md المكتشفة
الإنجليزية
النجوم
٩
التفرعات
٢

خيارات التثبيت

يُحدَّد Prompt الذي يراجع المصدر أولًا بشكل افتراضي. يمكنك التبديل إلى أمر مباشر أو تنزيل نسخة محلية.

مراجعة ملفات المصدر

اقرأ SKILL.md وأي ملفات مرافقة يعرضها SkillsMP قبل أن تقرر التثبيت.