windows-execution-analysis

Collect and analyze Windows process execution artifacts with Velociraptor.

Updated Aug 27, 2026
One-click install
npx skills add https://github.com/mgreen27/dfir-skills --skill windows-execution-analysis
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: windows-execution-analysis
Source: https://github.com/mgreen27/dfir-skills/tree/main/skills/windows-execution-analysis
Command: npx skills add https://github.com/mgreen27/dfir-skills --skill windows-execution-analysis

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill streamlines the collection and analysis of Windows process execution artifacts to support incident response investigations.

Core Features & Use Cases

  • Artifact Collection: Automatically gathers evidence of process execution from Windows clients, including registry and system timeline data.
  • Data Reuse & Validation: Reuses previous evidence collection when available, reducing redundant operations and ensuring data integrity.
  • Use Case: Investigators can quickly gather execution artifacts across multiple hosts to identify malicious activity and verify process behaviors during a breach investigation.

Quick Start

Use this Skill to collect execution artifacts from specified Windows hosts, then review the generated reports for suspicious activity.

Frequently Asked Questions about windows-execution-analysis

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I collect Windows process execution artifacts for incident response?

You can collect Windows process execution artifacts for incident response by using this Skill to automatically gather forensic evidence like registry user assists, prefetch files, and process timelines across multiple clients. It works with Velociraptor to streamline evidence collection.

What Windows forensic artifacts are needed to investigate process execution?

Key Windows forensic artifacts for investigating process execution include registry user assists, prefetch files, and system process timelines. This Skill targets these specific artifacts to help identify malicious activity and verify process behaviors during an investigation.

Can I use Velociraptor to gather process execution evidence across multiple hosts?

Yes, you can use Velociraptor with this Skill to gather process execution evidence across multiple Windows hosts. It automates collection from specified clients and generates reports that help investigators quickly identify suspicious activity during a breach.

Does this Windows forensic analysis tool reuse previously collected evidence?

Yes, this Windows forensic analysis tool reuses previously collected evidence when available. This reduces redundant collection operations across clients, saves time during incident response, and helps ensure data integrity throughout the investigation process.

What is the best way to analyze prefetch files and registry user assists during a breach investigation?

The best way to analyze prefetch files and registry user assists during a breach is to automate their collection and correlation with process timelines. This Skill integrates with Velociraptor to gather these artifacts and generate reports highlighting suspicious process behaviors.