Windows Artifacts (EZ Tools / Autoruns / Event Logs)
CommunityParse Windows execution and persistence evidence fast
Data & Analytics#execution evidence#windows forensics#persistence triage#event log analysis#autorunsc#evtx parsing#mft timeline
Authorrjonhaas
Version1.0.0
Installs0
System Documentation
What problem does it solve?
Windows incident response often stalls because analysts need reliable evidence of execution, persistence, and user activity across many host-based artifacts.
Core Features & Use Cases
- Execution evidence extraction: Pulls and parses Prefetch, Amcache, Shimcache/AppCompatCache, MFT/USN Change Journal, and timeline artifacts to reconstruct what ran and when.
- Persistence and autorun triage: Guides review of ASEP/Autorunsc outputs (services, drivers, tasks, boot execute, WMI, etc.) to identify suspicious enabled persistence.
- Event log investigation: Parses EVTX logs and highlights key authentication, process creation, PowerShell, RDP, Defender, task scheduler, WMI, and system events to connect host behavior to suspicious activity.
- Practical pivots and correlation: Uses hashes, timestamps, and artifacts’ paths to pivot across outputs and reduce false positives (e.g., timestomping confidence rules).
Quick Start
Run this skill by parsing Windows evidence artifacts into CSV outputs (Prefetch, Amcache/Shimcache, MFT/USN, and EVTX) and then pivot on hashes, timestamps, and suspicious paths to build an execution/persistence timeline.
Dependency Matrix
Required Modules
None requiredComponents
Standard packageđź’» Claude Code Installation
Recommended: Let Claude install automatically. Simply copy and paste the text below to Claude Code.
Please help me install this Skill: Name: Windows Artifacts (EZ Tools / Autoruns / Event Logs) Download link: https://github.com/rjonhaas/SIFTics/archive/main.zip#windows-artifacts-ez-tools-autoruns-event-logs Please download this .zip file, extract it, and install it in the .claude/skills/ directory.
Agent Skills Search Helper
Install a tiny helper to your Agent, search and equip skill from 471,000+ vetted skills library on demand.