Claude
Skills
Sign in
Back

analyzing-windows-amcache-artifacts

Included with Lifetime
$97 forever

Parse and analyze Windows Amcache.hve registry hive to extract program execution evidence, file metadata, SHA-1 hashes, and device connection history for digital forensics and incident response investigations.

Generalamcachewindows-forensicsregistry-analysisexecution-artifactsscripts

What this skill does


# Analyzing Windows Amcache Artifacts

Extract execution evidence from Amcache.hve including application paths,
SHA-1 hashes, timestamps, and publisher metadata for DFIR investigations.

Related in General