Skill Claude CodeCodex
Part of cybersec-toolkit
Parse Windows Prefetch files to determine program execution history including run counts, timestamps, and referenced files for forensic investigation.
25 tagged evidence-collection, measured the same way as everything else here.
Browse within: forensics 25windows-artifacts 16execution-history 9prefetch 9timeline-analysis 9artifact-analysis 7lnk-files 7registry-explorer 7regripper 7shortcut-analysis 7timeline-reconstruction 7windows-registry 7antigravity-skills 6bug-bounty 6
Skill Claude CodeCodex
Part of cybersec-toolkit
Parse Windows Prefetch files to determine program execution history including run counts, timestamps, and referenced files for forensic investigation.
pinkpixel-dev/skills-collection-1
Skill Claude CodeCodex
Parse Windows Prefetch files to determine program execution history including run counts, timestamps, and referenced files for forensic investigation.
pinkpixel-dev/skills-collection-1
Skill Claude CodeCodex
Parse Windows LNK shortcut files to extract target paths, timestamps, volume information, and machine identifiers for forensic timeline reconstruction.
pinkpixel-dev/skills-collection-1
Skill Claude CodeCodex
Extract and analyze Windows Registry hives to uncover user activity, installed software, autostart entries, and evidence of system compromise.
Skill Claude CodeCodex
Parse Windows Prefetch files (versions 17, 23, 26, 30) with tools like PECmd, WinPrefetchView, or python-prefetch to determine program execution history, including run counts, execution timestamps, and referenced files/DLLs. Use when building a timeline of program execution on a Windows system, confirming whether a…
Skill Claude CodeCodex
Parse Windows LNK shortcut files to extract target paths, MAC timestamps, volume serial numbers, and machine identifiers for forensic timeline reconstruction. Use when investigating recently-accessed files, tracking removable media or network paths referenced by shortcuts, or building a DFIR timeline from LNK…
Skill Claude CodeCodex
Extract and analyze Windows Registry hives with tools like RegRipper and Registry Explorer to uncover user activity, installed software, autostart/persistence entries, and evidence of system compromise. Use when investigating registry-based persistence, reconstructing user or system activity, or performing DFIR triage…
Skill Claude CodeCodex
Parse Windows Prefetch files to determine program execution history including run counts, timestamps, and referenced files for forensic investigation.
Skill Claude CodeCodex
Parse Windows LNK shortcut files to extract target paths, timestamps, volume information, and machine identifiers for forensic timeline reconstruction.
Skill Claude CodeCodex
Extract and analyze Windows Registry hives to uncover user activity, installed software, autostart entries, and evidence of system compromise.
marysatasselshaped667/skills-collection-1
Skill Claude CodeCodex
Parse Windows Prefetch files to determine program execution history including run counts, timestamps, and referenced files for forensic investigation.
marysatasselshaped667/skills-collection-1
Skill Claude CodeCodex
Parse Windows LNK shortcut files to extract target paths, timestamps, volume information, and machine identifiers for forensic timeline reconstruction.
marysatasselshaped667/skills-collection-1
Skill Claude CodeCodex
Extract and analyze Windows Registry hives to uncover user activity, installed software, autostart entries, and evidence of system compromise.
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: