windows-analysis

Collect and analyze Windows artifacts using Velociraptor for incident response.

Updated Aug 27, 2026
One-click install
npx skills add https://github.com/mgreen27/dfir-skills --skill windows-analysis
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: windows-analysis
Source: https://github.com/mgreen27/dfir-skills/tree/main/skills/windows-analysis
Command: npx skills add https://github.com/mgreen27/dfir-skills --skill windows-analysis

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill simplifies the workflow for analyzing Windows systems by enabling targeted artifact collection and investigation using Velociraptor.

Core Features & Use Cases

  • Investigation Workflow: Guides analysts through collecting and reviewing Windows event logs, registry data, and file activity artifacts.
  • Targeted Data Collection: Allows focused retrieval of suspicious processes, execution traces, or persistence mechanisms on Windows hosts.
  • Use Case: An investigator suspects malicious activity on a Windows machine and runs a Velociraptor-based query to identify malicious binaries, then records the hashes and metadata for further analysis.

Quick Start

Run Windows analysis artifacts against a Velociraptor client to identify suspicious artifacts or collect specific evidence.

Frequently Asked Questions about windows-analysis

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I collect Windows forensic artifacts using Velociraptor for incident response?

Windows forensic artifact collection using Velociraptor targets event logs, registry data, and file activity to support incident response. It guides analysts through focused retrieval of suspicious processes and execution traces on Windows hosts.

What is the best way to hunt for persistence mechanisms on a compromised Windows machine?

Hunting for persistence mechanisms on a Windows machine involves running targeted Velociraptor queries to identify suspicious processes and binaries. This allows investigators to record hashes and metadata for further analysis.

Can I use Velociraptor to reconstruct a timeline of malicious activity on Windows?

Velociraptor supports timeline reconstruction of Windows artifacts during incident response workflows. By collecting and reviewing file activity and execution traces, you can establish a comprehensive timeline of malicious behavior.

Do I need a Velociraptor client to investigate suspicious binaries on Windows?

A Velociraptor client is required to investigate suspicious binaries on Windows. The analysis runs Windows artifacts against the client to identify malicious files and collect specific evidence for incident response.

How does targeted Velociraptor artifact collection improve Windows incident response workflows?

Targeted Velociraptor artifact collection improves Windows incident response by ensuring safety and relevance of collected data. It allows focused retrieval of specific evidence rather than full system captures, streamlining investigation continuity.

What limitations exist when analyzing Windows event logs and registry data with Velociraptor?

Analysis of Windows event logs and registry data with Velociraptor focuses on targeted collection and investigation continuity. It emphasizes ease of use and data safety, but requires a connected client for successful evidence retrieval.