performing-windows-artifact-analysis-with-eric-zimmerman-tools
mukul975/Anthropic-Cybersecurity-Skills
This suite provides comprehensive utilities for digital forensic investigations, allowing users to analyze critical Windows artifacts. Tools like KAPE, MFTECmd, PECmd, and RECmd parse registry hives, $MFT records, prefetch files, and event logs. It is essential for building a robust timeline of program execution, file access patterns, and system persistence during DFIR incident response.