acquiring-disk-image-w…
Create forensically sound bit-for-bit disk images using dd and dcfldd while preserving evidence integrity through
Parses and analyzes the Windows Amcache.hve registry hive to extract evidence of program execution, application
$ npx -y skills add Mikaru0Mystic/sectinel --skill analyzing-windows-amcache-artifacts --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/analyzing-windows-amcache-artifactsContext preview
The summary Claude sees to decide when to auto-load this skill.
Parses and analyzes the Windows Amcache.hve registry hive to extract evidence of program execution, application
name: analyzing-windows-amcache-artifacts description: 'Parses and analyzes the Windows Amcache.hve registry hive to extract evidence of program execution, application installation, and driver loading for digital forensics investigations. Uses Eric Zimmerman''s AmcacheParser and Timeline Explorer for artifact extraction, SHA-1 hash correlation with threat intel, and timeline reconstruction. Activates for requests involving Amcache forensics, program execution evidence, Windows artifact analysis, or application compatibility cache investigation. ' domain: cybersecurity subdomain: digital-forensics tags: - amcache - windows-forensics - program-execution - AmcacheParser - eric-zimmerman - timeline-analysis - DFIR version: 1.0.0 author: mahipal license: Apache-2.0 nist_csf: - RS.AN-01 - RS.AN-03 - DE.AE-02 - RS.MA-01
**Do not use** as sole proof of program execution. Amcache proves file existence and metadata registration, but ShimCache (AppCompatCache) and Prefetch provide stronger execution evidence. Use all three artifacts together for conclusive analysis.
Extract the Amcache hive from a forensic image or live system:
# From a live system (requires elevated privileges and raw copy tool) # Amcache.hve is locked by the system; use a raw disk copy tool # Option A: FTK Imager - mount image and navigate to: # C:\Windows\appcompat\Programs\Amcache.hve # Also collect: Amcache.hve.LOG1, Amcache.hve.LOG2 # Option B: Using KAPE for automated triage collection kape.exe --tsource C: --tdest D:\Evidence\%m --target Amcache # Option C: From a mounted forensic image (E: = mounted image) copy "E:\Windows\appcompat\Programs\Amcache.hve" D:\Evidence\ copy "E:\Windows\appcompat\Programs\Amcache.hve.LOG1" D:\Evidence\ copy "E:\Windows\appcompat\Programs\Amcache.hve.LOG2" D:\Evidence\
Always collect the transaction log files (`.LOG1`, `.LOG2`) alongside the hive. AmcacheParser replays uncommitted transactions from these logs to recover the most complete data.
Run AmcacheParser against the acquired hive:
# Basic parsing with CSV output AmcacheParser.exe -f "D:\Evidence\Amcache.hve" --csv "D:\Evidence\Output" # Parse with a SHA-1 whitelist to exclude known-good entries (NSRL) AmcacheParser.exe -f "D:\Evidence\Amcache.hve" -w "D:\Whitelists\nsrl_sha1.txt" --csv "D:\Evidence\Output" # Parse with a SHA-1 inclusion list (only show matches against known-bad hashes) AmcacheParser.exe -f "D:\Evidence\Amcache.hve" -b "D:\IOCs\malware_sha1.txt" --csv "D:\Evidence\Output" # Include deleted entries with high-precision timestamps AmcacheParser.exe -f "D:\Evidence\Amcache.hve" --csv "D:\Evidence\Output" -i --mp
AmcacheParser produces multiple CSV files in the output directory:
| Output File | Contents | |-------------|----------| | `Amcache_AssociatedFileEntries.csv` | File entries with SHA-1 hashes, paths, sizes, and timestamps | | `Amcache_UnassociatedFileEntries.csv` | Orphaned file entries from older Amcache format | | `Amcache_ProgramEntries.csv` | Installed program metadata (name, publisher, version, install date) | | `Amcache_DeviceContainers.csv` | USB and device connection history | | `Amcache_DevicePnps.csv` | Plug-and-Play device driver information | | `Amcache_DriverBinaries.csv` | Loaded driver binaries with paths and hashes |
Open the `AssociatedFileEntries.csv` in Timeline Explorer and examine key columns:
Key columns to review: - ProgramId : Links file to its parent program entry - SHA1 : Hash for threat intel lookups - FullPath : Original file location on disk - FileSize : Size of the executable - FileKeyLastWriteTimestamp : When the Amcache entry was last updated - Name : File name - Publisher : Code signing publisher (blank = unsigned) - BinProductVersion : Version string from the PE header - LinkDate : PE compilation timestamp (useful for detecting timestomping)
Filter for suspicious indicators:
# In Timeline Explorer, apply these filters: # 1. Find unsigned executables (potentially malicious) Publisher column = (empty) # 2. Find executables from suspicious paths FullPath contains: \temp\, \appdata\, \downloads\, \public\, \programdata\ # 3. Find executables with recent timestamps during incident window FileKeyLastWriteTimestamp between: 2026-03-15 00:00:00 and 2026-03-16 00:00:00 # 4. Find executables with suspicious compilation dates (timestomping) LinkDate year < 2015 AND FileKeyLastWriteTimestamp year = 2026
Extract SHA-1 hashes and check against
Open-source security arsenal for AI coding agents: 784 cybersecurity skills, scanner integrations, and a security MCP for Claude Code, Cursor, opencode, Gemini CLI, Cline, and any agentskills.io agent. Mapped to OWASP, MITRE ATT&CK, NIST CSF, D3FEND, ATLAS.
Repo: Mikaru0Mystic/sectinel
Create forensically sound bit-for-bit disk images using dd and dcfldd while preserving evidence integrity through
Detect dangerous ACL misconfigurations in Active Directory using ldap3 to identify GenericAll, WriteDACL, and
Perform static analysis of Android APK malware samples using apktool for decompilation, jadx for Java source
Parses API Gateway access logs (AWS API Gateway, Kong, Nginx) to detect BOLA/IDOR attacks, rate limit bypass,
Analyze advanced persistent threat (APT) group techniques using MITRE ATT&CK Navigator to create layered heatmaps
Queries Azure Monitor activity logs and sign-in logs via azure-monitor-query to detect suspicious administrative