tag

timeline-analysis

5 indexed skills · max 10 per page

skills (5)

building-incident-timeline-with-timesketch

mukul975/Anthropic-Cybersecurity-Skills · building-incident-timeline-with-timesketch

0

Build collaborative forensic incident timelines using Timesketch to ingest, normalize, and analyze multi-source event data for attack chain reconstruction and investigation documentation.

analyzing-prefetch-files-for-execution-history

mukul975/Anthropic-Cybersecurity-Skills · analyzing-prefetch-files-for-execution-history

0

Parse Windows Prefetch files to determine program execution history including run counts, timestamps, and referenced files for forensic investigation.

performing-timeline-reconstruction-with-plaso

mukul975/Anthropic-Cybersecurity-Skills · performing-timeline-reconstruction-with-plaso

0

Build comprehensive forensic super-timelines using Plaso (log2timeline) to correlate events across file systems, logs, and artifacts into a unified chronological view.

performing-log-analysis-for-forensic-investigation

mukul975/Anthropic-Cybersecurity-Skills · performing-log-analysis-for-forensic-investigation

0

Collect, parse, and correlate system, application, and security logs to reconstruct events and establish timelines during forensic investigations.

analyzing-windows-amcache-artifacts

mukul975/Anthropic-Cybersecurity-Skills · analyzing-windows-amcache-artifacts

0

Parses and analyzes the Windows Amcache.hve registry hive to extract evidence of program execution, application installation, and driver loading for digital forensics investigations. Uses Eric Zimmerman's AmcacheParser and Timeline Explorer for artifact extraction, SHA-1 hash correlation with threat intel, and timeline reconstruction. Activates for requests involving Amcache forensics, program execution evidence, Windows artifact analysis, or application compatibility cache investigation.