external/anthropic-cybersecurity-skills/skills/parsing-artifacts-with-eric-zimmerman-tools/SKILL.md
Parse registry, prefetch, shellbags, and MFT with EZ Tools and Timeline Explorer.
npx skillsauth add seikaikyo/dash-skills parsing-artifacts-with-eric-zimmerman-toolsInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Authorized Use Only: These tools parse evidence acquired from systems. Only analyze data you are authorized to handle, maintain chain of custody, and work from forensic copies rather than originals.
Eric Zimmerman's Tools (EZ Tools) are a free, open-source suite of high-fidelity Windows forensic parsers, each focused on a specific artifact class and each producing analyst-ready CSV/JSON output. They are the de facto standard for Windows artifact analysis and are what KAPE's !EZParser module invokes under the hood. Key tools include:
$MFT, $J ($UsnJrnl), $Boot, $SDS, and $LogFile from NTFS volumes..pf) for evidence of program execution.UsrClass.dat/NTUSER.DAT.Amcache.hve for application execution and metadata.SYSTEM hive.Output is designed to load into Timeline Explorer (also by Eric Zimmerman), a fast CSV/Excel viewer purpose-built for filtering, tagging, and pivoting across forensic CSVs. The 2025+ releases run on .NET and also work natively on Linux.
# Download/update all .NET 6 tools into C:\Tools\EZ
.\Get-ZimmermanTools.ps1 -Dest C:\Tools\EZ
Source: https://ericzimmerman.github.io/ and https://github.com/EricZimmerman/Get-ZimmermanTools| ID | Official Technique Name | Relevance to this skill | |----|------------------------|--------------------------| | T1112 | Modify Registry | RECmd, AmcacheParser, and AppCompatCacheParser parse registry-resident artifacts; analysts use them to detect adversary registry modification (persistence, defense evasion) recorded in hives. |
These are defensive parsers; the mapping reflects the artifact (registry) most relevant to the adversary behavior they help uncover.
Keep parsers current so they handle the latest artifact formats.
.\Get-ZimmermanTools.ps1 -Dest C:\Tools\EZ
-f points at a single $MFT; --csv sets the output directory and --csvf the filename. Add --csvf for $J/UsnJrnl with -f $J.
MFTECmd.exe -f "E:\collection\C\$MFT" --csv "E:\out\mft" --csvf MFT.csv
REM Parse the USN Journal change log
MFTECmd.exe -f "E:\collection\C\$Extend\$J" --csv "E:\out\mft" --csvf UsnJrnl.csv
-d recurses a directory of .pf files. Output CSV + JSON.
PECmd.exe -d "E:\collection\C\Windows\Prefetch" --csv "E:\out\prefetch" --csvf Prefetch.csv --json "E:\out\prefetch\json"
-d points at the directory containing the user's UsrClass.dat/NTUSER.DAT (or -f a single hive).
SBECmd.exe -d "E:\collection\C\Users\jsmith" --csv "E:\out\shellbags"
RECmd is driven by batch files (--bn) that bundle plugins; the Kroll_Batch file is comprehensive. -d recurses a directory of hives.
RECmd.exe -d "E:\collection\C\Windows\System32\config" --bn "C:\Tools\EZ\RECmd\BatchExamples\Kroll_Batch.reb" --csv "E:\out\registry" --csvf Registry.csv
REM Search a single hive for a value/key
RECmd.exe -f "E:\collection\C\Users\jsmith\NTUSER.DAT" --sk "Run" --csv "E:\out\registry"
AmcacheParser.exe -f "E:\collection\C\Windows\AppCompat\Programs\Amcache.hve" --csv "E:\out\amcache" -i
AppCompatCacheParser.exe -f "E:\collection\C\Windows\System32\config\SYSTEM" --csv "E:\out\shimcache"
LECmd.exe -d "E:\collection\C\Users\jsmith\AppData\Roaming\Microsoft\Windows\Recent" --csv "E:\out\lnk"
JLECmd.exe -d "E:\collection\C\Users\jsmith\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations" --csv "E:\out\jumplists"
EvtxECmd.exe -d "E:\collection\C\Windows\System32\winevt\Logs" --csv "E:\out\evtx" --csvf EventLogs.csv
Open the resulting CSVs in Timeline Explorer (TimelineExplorer.exe). Use column filters, conditional formatting, and tagging to pivot on time, file path, and user. CSVs from all EZ Tools share consistent timestamp columns for cross-artifact correlation.
Build a working theory by correlating PECmd (execution time) with MFTECmd (file creation), Amcache/ShimCache (program presence), and ShellBags/LNK (access), all anchored on UTC timestamps.
| Tool | Artifact parsed | Link | |------|-----------------|------| | MFTECmd | $MFT, $J, $Boot, $SDS, $LogFile | https://github.com/EricZimmerman/MFTECmd | | PECmd | Prefetch | https://github.com/EricZimmerman/PECmd | | RECmd | Registry hives | https://github.com/EricZimmerman/RECmd | | SBECmd | ShellBags | https://github.com/EricZimmerman/Shellbags | | AmcacheParser | Amcache.hve | https://github.com/EricZimmerman/AmcacheParser | | AppCompatCacheParser | ShimCache | https://github.com/EricZimmerman/AppCompatCacheParser | | LECmd / JLECmd | LNK / Jump Lists | https://ericzimmerman.github.io/ | | EvtxECmd | EVTX event logs | https://github.com/EricZimmerman/evtx | | Timeline Explorer | CSV analysis viewer | https://ericzimmerman.github.io/ | | Get-ZimmermanTools | Downloader/updater | https://github.com/EricZimmerman/Get-ZimmermanTools |
| Flag | Meaning |
|------|---------|
| -f <file> | Parse a single file |
| -d <dir> | Recurse a directory |
| --csv <dir> | CSV output directory |
| --csvf <name> | CSV output filename |
| --json <dir> | JSON output directory |
| --bn <file> | RECmd batch (.reb) file |
| -i | AmcacheParser: include file entries (unassociated) |
development
拋棄式 HTML mockup 比稿:產出 2 到 3 個設計立場不同的變體(密度 / 版式 / 強調軸,不是換色),各附取捨說明,最後給有立場的對比結論。適用:「畫個草圖」「比較 A 版 B 版」「先看方向再做」「給我看幾種做法」。要 production 元件或設計已定案時不適用。
tools
需求不明時的意圖萃取訪談:一次一題、每題附上自己的猜測、聽出「真正想要 vs 覺得應該要」,直到能預測使用者反應(約 95% 信心)才動工。適用:需求缺少對象 / 動機 / 成功標準 / 約束,或使用者點名「訪談我」「先確認一下」「我們確定嗎」。明確自足的指示、純資訊查詢、機械性操作不適用。
development
對非平凡決策啟動新鮮 context 對抗審查(找碴不背書),在修正還便宜的時候抓出錯誤方向。適用:高風險改動(production、資安敏感邏輯、不可逆操作)、不熟的程式碼、要宣稱「這樣是安全的 / 可行的」之前。機械性操作與一行修改不適用。
testing
Reference for writing and editing agent skills well — the vocabulary and principles that make a skill predictable. Consult when authoring, reviewing, or pruning a SKILL.md.