evidence-collection skills

25 tagged evidence-collection, measured the same way as everything else here.

Browse within: forensics 25windows-artifacts 16execution-history 9prefetch 9timeline-analysis 9artifact-analysis 7lnk-files 7registry-explorer 7regripper 7shortcut-analysis 7timeline-reconstruction 7windows-registry 7antigravity-skills 6bug-bounty 6

Youngmaidainon/Agent-Level-Up

Skill Claude CodeCodex

Parse Windows Prefetch files (versions 17, 23, 26, 30) with tools like PECmd, WinPrefetchView, or python-prefetch to determine program execution history, including run counts, execution timestamps, and referenced files/DLLs. Use when building a timeline of program execution on a Windows system, confirming whether a…

not rated 3 9d ago A 98 tokens MIT

Youngmaidainon/Agent-Level-Up

Skill Claude CodeCodex

Parse Windows LNK shortcut files to extract target paths, MAC timestamps, volume serial numbers, and machine identifiers for forensic timeline reconstruction. Use when investigating recently-accessed files, tracking removable media or network paths referenced by shortcuts, or building a DFIR timeline from LNK…

not rated 3 9d ago A 67 tokens MIT

Youngmaidainon/Agent-Level-Up

Skill Claude CodeCodex

Extract and analyze Windows Registry hives with tools like RegRipper and Registry Explorer to uncover user activity, installed software, autostart/persistence entries, and evidence of system compromise. Use when investigating registry-based persistence, reconstructing user or system activity, or performing DFIR triage…

not rated 3 9d ago A 73 tokens MIT

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: