Skip to main content

investigating-windows-endpoints

Investigate a live or triaged Windows host for intrusion evidence using disk and registry artifacts — MFT/$UsnJrnl, registry hives, AmCache/ShimCache, Prefetch, LNK/JumpLists, ShellBags, and event logs — parsed with the Eric Zimmerman suite and consolidated into a timeline. Use when a Windows endpoint is suspect and you need execution, persistence, and access evidence from on-disk artifacts. Preserve order of volatility first; a running command is a write to the evidence.

Aller à l'installation

Informations de source

Dépôt
EvilFreelancer/secs
Dernière activité de la source
8 août 2026 à 20:56
Langue détectée de SKILL.md
anglais
Étoiles
9
Forks
2

Options d'installation

Le prompt qui vérifie d'abord la source est sélectionné par défaut. Vous pouvez passer à une commande directe ou télécharger une copie locale.

Vérifiez les fichiers source

Lisez SKILL.md et les fichiers associés affichés par SkillsMP avant de décider de l'installer.