Files
Anthropic-Cybersecurity-Skills/skills/analyzing-windows-amcache-artifacts/SKILL.md
T

645 B

name, description, domain, subdomain, tags, version, author, license
name description domain subdomain tags version author license
analyzing-windows-amcache-artifacts Parse and analyze Windows Amcache.hve registry hive to extract program execution evidence, file metadata, SHA-1 hashes, and device connection history for digital forensics and incident response investigations. cybersecurity digital-forensics
amcache
windows-forensics
registry-analysis
execution-artifacts
1.0 mahipal Apache-2.0

Analyzing Windows Amcache Artifacts

Extract execution evidence from Amcache.hve including application paths, SHA-1 hashes, timestamps, and publisher metadata for DFIR investigations.