Agent skill

LNK and Jump List Forensics

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

Apache-2.0Auto-check passedSecurity

Install LNK and Jump List Forensics

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill analyzing-lnk-file-and-jump-list-artifacts -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills analyzing-lnk-file-and-jump-list-artifacts --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/analyzing-lnk-file-and-jump-list-artifacts .claude/skills/analyzing-lnk-file-and-jump-list-artifacts && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
analyzing-lnk-file-and-jump-list-artifacts
GitHub stars
34k
Token cost
~2.8k tokens
SKILL.md length
585 words
Files
8 (incl. scripts, references, assets)
Skills in repo
644
Repo updated
First seen
Licence
Apache-2.0

At a glance

Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

  • Works in 3 steps: Parse LNK files from Recent folder to… → Cross-reference with MFT timestamps and… → Note that LNK files persist even after…
  • Reconstructing which files a user opened on a Windows machine
  • SKILL.md covers Overview, When to Use, Prerequisites and LNK File Locations, plus 8 more sections
  • Runs Python scripts from its folder

What it does

Windows creates LNK files when a user opens a file through Explorer or an Open/Save dialog, and they record the target's original path, timestamps, volume serial number, NetBIOS name and the host's MAC address. Jump Lists, which arrived with Windows 7, keep per-application lists of recent and frequent files. Both can outlive the target file, so they help show that a user touched specific files at specific times.

The skill lists where LNK files live (the Recent folder, Desktop, Start Menu and Office recent documents), lays out the 76-byte Shell Link header field by field and points out the forensic fields worth extracting, such as target timestamps, volume details and network share paths. Tooling is LECmd and JLECmd by Eric Zimmerman, Python libraries for manual parsing and Timeline Explorer for CSV review. The folder adds agent.py and process.py scripts, reference notes on workflows and standards, and a report template.

When your agent uses it

  • Reconstructing which files a user opened on a Windows machine
  • Showing that a file was accessed even though it has since been deleted
  • Building a timeline of program execution from Jump Lists
  • Reviewing recent and frequently used file evidence during a forensic exam

Example prompts

  • “Parse the Recent folder from this triage collection with LECmd and list the files that were opened.”
  • “Run JLECmd on the Jump Lists in the image and build a timeline of accessed documents.”
  • “Show me the volume serial number and timestamps stored in invoice.lnk.”
  • “Which LNK files in this collection point at network shares?”

Requirements

  • LECmd and JLECmd from Eric Zimmerman
  • Python 3.8 or newer with pylnk3 or LnkParse3
  • A forensic image or triage collection from a Windows system
  • Timeline Explorer for CSV analysis

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Parse LNK files from Recent folder to identify accessed documents
  2. Cross-reference with MFT timestamps and USN Journal entries
  3. Note that LNK files persist even after target files are deleted

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • docs.microsoft.com
    • magnetforensics.com
    • cybertriage.com
    • ericzimmerman.github.io

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

LNK and Jump List Forensics loads about 2.8k tokens when it runs, and up to ~4.1k if it reads all its reference files. Until then it costs about 117 tokens; SKILL.md has 585 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~117
When it runs · the whole SKILL.md, loaded when a task matches
~2.8k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 585 words, ~2,825 tokens.

Download SKILL.mdSave it as .claude/skills/analyzing-lnk-file-and-jump-list-artifacts/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
analyzing-lnk-file-and-jump-list-artifacts
description
Analyze Windows LNK shortcut files and Jump List artifacts with LECmd, JLECmd, and manual Shell Link Binary Format parsing to establish evidence of file access, program execution, and user activity that persists even after the target file is deleted. Use when investigating Windows user activity, reconstructing file-access or program-execution timelines, or examining recent/frequently-used file evidence in a forensic exam.
domain
cybersecurity
subdomain
digital-forensics
tags
lnk-files, jump-lists, lecmd, jlecmd, windows-forensics, shell-link, user-activity, file-access, program-execution, recent-files
version
1.0
author
mahipal
license
Apache-2.0
nist_csf
RS.AN-03, DE.AE-02, RS.MA-01
mitre_attack
T1547.009, T1204.002, T1059.001

Analyzing LNK File and Jump List Artifacts

Overview

Windows LNK (shortcut) files and Jump Lists are critical forensic artifacts that provide evidence of file access, program execution, and user behavior. LNK files are created automatically when a user opens a file through Windows Explorer or the Open/Save dialog, storing metadata about the target file including its original path, timestamps, volume serial number, NetBIOS name, and MAC address of the host system. Jump Lists, introduced in Windows 7, extend this by maintaining per-application lists of recently and frequently accessed files. These artifacts persist even after the target files are deleted, making them invaluable for establishing that a user accessed specific files at specific times.

When to Use

  • When investigating security incidents that require analyzing lnk file and jump list artifacts
  • When building detection rules or threat hunting queries for this domain
  • When SOC analysts need structured procedures for this analysis type
  • When validating security monitoring coverage for related attack techniques

Prerequisites

  • LECmd (Eric Zimmerman) for LNK file parsing
  • JLECmd (Eric Zimmerman) for Jump List parsing
  • Python 3.8+ with pylnk3 or LnkParse3 libraries
  • Forensic image or triage collection from Windows system
  • Timeline Explorer for CSV analysis

LNK File Locations

LocationDescription
%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Recent\Recent files accessed
%USERPROFILE%\Desktop\User-created shortcuts
%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Start Menu\Start Menu shortcuts
%USERPROFILE%\AppData\Roaming\Microsoft\Office\Recent\Office recent documents

LNK File Structure

OffsetSizeField
0x004HeaderSize (always 0x0000004C)
0x0416LinkCLSID (always 00021401-0000-0000-C000-000000000046)
0x144LinkFlags
0x184FileAttributes
0x1C8CreationTime (FILETIME)
0x248AccessTime (FILETIME)
0x2C8WriteTime (FILETIME)
0x344FileSize of target
0x384IconIndex
0x3C4ShowCommand
0x402HotKey
Key Forensic Fields in LNK Files
  • Target file timestamps: Creation, access, modification times of the referenced file
  • Volume information: Serial number, drive type, volume label
  • Network share information: UNC path, share name
  • Machine identifiers: NetBIOS name, MAC address (from TrackerDataBlock)
  • Distributed Link Tracking: Machine ID and object GUID

Analysis with EZ Tools

LECmd - LNK File Parser
powershell
# Parse all LNK files in Recent folder
LECmd.exe -d "C:\Evidence\Users\suspect\AppData\Roaming\Microsoft\Windows\Recent" --csv C:\Output --csvf lnk_analysis.csv

# Parse a single LNK file with full details
LECmd.exe -f "C:\Evidence\Users\suspect\Desktop\Confidential.docx.lnk" --json C:\Output

# Parse LNK files with additional detail levels
LECmd.exe -d "C:\Evidence\Users\suspect\AppData\Roaming\Microsoft\Windows\Recent" --csv C:\Output --csvf lnk_all.csv --all
JLECmd - Jump List Parser
powershell
# Parse Automatic Jump Lists
JLECmd.exe -d "C:\Evidence\Users\suspect\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations" --csv C:\Output --csvf jumplists_auto.csv

# Parse Custom Jump Lists
JLECmd.exe -d "C:\Evidence\Users\suspect\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations" --csv C:\Output --csvf jumplists_custom.csv

# Parse all jump lists with detailed output
JLECmd.exe -d "C:\Evidence\Users\suspect\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations" --csv C:\Output --csvf jumplists_auto.csv --ld

Jump List Structure

Show full SKILL.md (254 more words)Show less
Automatic Destinations (automaticDestinations-ms)

These are OLE Compound files (Structured Storage) identified by AppID hash in the filename:

AppID HashApplication
5f7b5f1e01b83767Windows Explorer Pinned/Frequent
1b4dd67f29cb1962Windows Explorer Recent
9b9cdc69c1c24e2bNotepad
a7bd71699cd38d1cNotepad++
12dc1ea8e34b5a6Microsoft Paint
7e4dca80246863e3Control Panel
1cf97c38a5881255Microsoft Edge
f01b4d95cf55d32aWindows Explorer
9d1f905ce5044aeeMicrosoft Excel
a4a5324453625195Microsoft Word
d00655d2aa12ff6dMicrosoft PowerPoint
bc03160ee1a59fc1Outlook
Custom Destinations (customDestinations-ms)

Created when users pin items to application jump lists. These files contain sequential LNK entries.

Python Analysis Script

python
import struct
import os
from datetime import datetime, timedelta

FILETIME_EPOCH = datetime(1601, 1, 1)

def filetime_to_datetime(filetime_bytes: bytes) -> datetime:
    """Convert Windows FILETIME (100-ns intervals since 1601) to datetime."""
    ft = struct.unpack("<Q", filetime_bytes)[0]
    if ft == 0:
        return None
    return FILETIME_EPOCH + timedelta(microseconds=ft // 10)

def parse_lnk_header(lnk_path: str) -> dict:
    """Parse the Shell Link header from an LNK file."""
    with open(lnk_path, "rb") as f:
        header = f.read(76)

    header_size = struct.unpack("<I", header[0:4])[0]
    if header_size != 0x4C:
        return {"error": "Invalid LNK header"}

    link_flags = struct.unpack("<I", header[0x14:0x18])[0]
    file_attrs = struct.unpack("<I", header[0x18:0x1C])[0]

    result = {
        "header_size": header_size,
        "link_flags": hex(link_flags),
        "file_attributes": hex(file_attrs),
        "creation_time": filetime_to_datetime(header[0x1C:0x24]),
        "access_time": filetime_to_datetime(header[0x24:0x2C]),
        "write_time": filetime_to_datetime(header[0x2C:0x34]),
        "file_size": struct.unpack("<I", header[0x34:0x38])[0],
        "has_target_id_list": bool(link_flags & 0x01),
        "has_link_info": bool(link_flags & 0x02),
        "has_name": bool(link_flags & 0x04),
        "has_relative_path": bool(link_flags & 0x08),
        "has_working_dir": bool(link_flags & 0x10),
        "has_arguments": bool(link_flags & 0x20),
        "has_icon_location": bool(link_flags & 0x40),
    }
    return result

Investigation Use Cases

Evidence of File Access
  1. Parse LNK files from Recent folder to identify accessed documents
  2. Cross-reference with MFT timestamps and USN Journal entries
  3. Note that LNK files persist even after target files are deleted
Removable Media Access
  1. LNK files referencing drive letters E:, F:, G: indicate removable media usage
  2. Volume serial number in LNK identifies the specific device
  3. MAC address in TrackerDataBlock identifies the source machine
Network Share Activity
  1. LNK files with UNC paths (\server\share) indicate network file access
  2. NetBIOS name identifies the remote server
  3. Timestamps establish when access occurred

Differences Between Windows 10 and Windows 11

Recent research (IEEE 2025) shows that Windows 11 produces different LNK and Jump List artifacts:

  • Fewer automatic LNK files generated for certain file types
  • Modified Jump List behavior for modern applications
  • UWP/MSIX applications may not generate traditional Jump Lists
  • Windows 11 Quick Access replaces some Recent functionality

References

Example Output

text
$ LECmd.exe -d "C:\Evidence\Users\jsmith\AppData\Roaming\Microsoft\Windows\Recent" --csv /analysis/lnk_output

LECmd v1.11.0 - LNK File Parser
================================

Processing 47 LNK files...

--- LNK File: Q4_Report.xlsx.lnk ---
  Source:           C:\Evidence\Users\jsmith\Recent\Q4_Report.xlsx.lnk
  Target Path:      C:\Users\jsmith\Downloads\Q4_Report.xlsm
  Target Created:   2024-01-15 14:33:45 UTC
  Target Modified:  2024-01-15 14:33:45 UTC
  Target Accessed:  2024-01-15 14:35:12 UTC
  File Size:        251,904 bytes
  Drive Type:       Fixed (C:)
  Volume Serial:    A4E7-3F21
  Machine ID:       DESKTOP-J5M1TH
  MAC Address:      48:2A:E3:5C:9B:01

--- LNK File: update_client.exe.lnk ---
  Source:           C:\Evidence\Users\jsmith\Recent\update_client.exe.lnk
  Target Path:      C:\ProgramData\Updates\update_client.exe
  Target Created:   2024-01-15 14:34:02 UTC
  Target Modified:  2024-01-15 14:34:02 UTC
  Target Accessed:  2024-01-15 14:36:30 UTC
  File Size:        1,258,496 bytes
  Drive Type:       Fixed (C:)
  Volume Serial:    A4E7-3F21
  Machine ID:       DESKTOP-J5M1TH
  Working Dir:      C:\ProgramData\Updates
  Arguments:        --silent --no-update-check
  Run Window:       Hidden

======================================================================

$ JLECmd.exe -d "C:\Evidence\Users\jsmith\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations" --csv /analysis/jumplist_output

JLECmd v1.5.0 - Jump List Parser
==================================

Processing 23 AutomaticDestinations files...

--- Application: Microsoft Excel (AppID: 12dc1ea8e34b5a6) ---
  Entries: 15
  Most Recent:
    Entry 0:  C:\Users\jsmith\Downloads\Q4_Report.xlsm         (2024-01-15 14:35:12 UTC)
    Entry 1:  \\FILESERV01\Finance\Budget_2024.xlsx             (2024-01-14 09:22:30 UTC)
    Entry 2:  C:\Users\jsmith\Documents\Expenses\Dec2023.xlsx   (2024-01-10 16:45:00 UTC)

--- Application: Windows Explorer (AppID: f01b4d95cf55d32a) ---
  Entries: 28
  Most Recent:
    Entry 0:  C:\ProgramData\Updates\                           (2024-01-15 14:36:25 UTC)
    Entry 1:  E:\Backup\                                        (2024-01-15 15:30:00 UTC)
    Entry 2:  \\FILESERV01\HR\Employees\                        (2024-01-15 16:12:45 UTC)

--- Application: cmd.exe (AppID: 9b9cdc69c1c24e2b) ---
  Entries: 5
  Most Recent:
    Entry 0:  C:\Windows\System32\cmd.exe                       (2024-01-15 14:36:00 UTC)

Summary:
  Total LNK files processed:    47
  Total Jump List entries:       156
  Suspicious artifacts:          3 (hidden window execution, USB drive access, network shares)
  CSV exported to:               /analysis/lnk_output/ and /analysis/jumplist_output/

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files (scripts, references, assets) in skills/analyzing-lnk-file-and-jump-list-artifacts of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • assets/template.md
  • references/api-reference.md
  • references/standards.md
  • references/workflows.md
  • scripts/agent.py
  • scripts/process.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

LNK and Jump List Forensics next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

LNK and Jump List Forensics compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
LNK and Jump List Forensics this skillmukul975/Anthropic-Cybersecurity-Skills34k—~2.8kAutomated safety check: PassApache-2.0
Auditing Python Dependenciesjeremylongshore/tons-of-skills-marketplace2.8k—~2.3kAutomated safety check: NotesMIT
Re Mobile Forensicsdslsdzc/rev-skills135—~1.6kAutomated safety check: PassApache-2.0
Security Auditoreigent-ai/eigent15k—~1.8kAutomated safety check: NotesApache-2.0
CodeQL Security Scantrailofbits/skills7.5k—~4.6kAutomated safety check: NotesCC-BY-SA-4.0
Kedro Security Reviewkedro-org/kedro11k—~3.3kAutomated safety check: PassCustom licence

Similar skills

  • Auditing Python Dependencies

    jeremylongshore/tons-of-skills-marketplace

    Audit a Python project's installed dependencies for known CVEs by wrapping pip-audit (PyPA's official vulnerability auditor) and emitting findings in the canonical penetration-tester schema.

    2.8k GitHub stars~2.3k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Re Mobile Forensics

    dslsdzc/rev-skills

    移动设备取证:Android/iOS 备份解析、应用数据提取、删除恢复与时间线. An agent skill from dslsdzc/rev-skills.

    135 GitHub stars~1.6k tokensUpdated 6 days ago
    MobileAuto-check passed
  • Security Auditor

    eigent-ai/eigent

    Audits source code, dependencies and config files for vulnerabilities and hardcoded secrets, using two bundled Python scanners and an OWASP Top 10 checklist.

    15k GitHub stars~1.8k tokensUpdated yesterday
    SecurityAuto-check: notes
  • CodeQL Security Scan

    trailofbits/skills

    Official

    Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.

    7.5k GitHub stars~4.6k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Kedro Security Review

    kedro-org/kedro

    Run a Kedro security scan on the full codebase or just a pull request.

    11k GitHub stars~3.3k tokensUpdated 2 days ago
    SecurityAuto-check passed
  • A skill your agent uses when modifying, testing, documenting, or reviewing the Vulners Python SDK.

    376 GitHub stars~2.3k tokensUpdated 12 days ago
    SecurityAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 644 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed
  • ATT&CK Threat Actor Mapping

    mukul975/Anthropic-Cybersecurity-Skills

    Maps threat actor behavior and observed indicators to MITRE ATT&CK, builds Navigator coverage heatmaps, finds detection gaps and produces threat intelligence reports.

    34k GitHub stars~2.5k tokensUpdated 1 mo ago
    Auto-check passed

Works with

Categories

Questions about LNK and Jump List Forensics

What does LNK and Jump List Forensics do?

Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution. Windows creates LNK files when a user opens a file through Explorer or an Open/Save dialog, and they record the target's original path, timestamps, volume serial number, NetBIOS name and the host's MAC address. Jump Lists, which arrived with Windows 7, keep per-application lists of recent and frequent files.

When should I use LNK and Jump List Forensics?

LNK and Jump List Forensics fits situations like: reconstructing which files a user opened on a Windows machine; showing that a file was accessed even though it has since been deleted; building a timeline of program execution from Jump Lists; reviewing recent and frequently used file evidence during a forensic exam.

How do I install LNK and Jump List Forensics in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill analyzing-lnk-file-and-jump-list-artifacts -a claude-code`. Or copy the skill folder (skills/analyzing-lnk-file-and-jump-list-artifacts in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/analyzing-lnk-file-and-jump-list-artifacts in your project. Claude Code loads it when a task matches its description.

How do I install LNK and Jump List Forensics in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill analyzing-lnk-file-and-jump-list-artifacts -a codex`. Or copy the skill folder (skills/analyzing-lnk-file-and-jump-list-artifacts in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/analyzing-lnk-file-and-jump-list-artifacts in your project. Codex loads it when a task matches its description.

Can I use LNK and Jump List Forensics in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill analyzing-lnk-file-and-jump-list-artifacts -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/analyzing-lnk-file-and-jump-list-artifacts, .gemini/skills/analyzing-lnk-file-and-jump-list-artifacts, .github/skills/analyzing-lnk-file-and-jump-list-artifacts and .opencode/skills/analyzing-lnk-file-and-jump-list-artifacts in your project.

What does LNK and Jump List Forensics need to run?

Going by SKILL.md and its folder, LNK and Jump List Forensics needs Python for the scripts in its folder. Our summary lists: LECmd and JLECmd from Eric Zimmerman; Python 3.8 or newer with pylnk3 or LnkParse3; A forensic image or triage collection from a Windows system; Timeline Explorer for CSV analysis.

Does LNK and Jump List Forensics access the network?

SKILL.md names 4 domains. As links in the text: docs.microsoft.com, magnetforensics.com, cybertriage.com and ericzimmerman.github.io. This is read from the text; nothing was executed.

Is LNK and Jump List Forensics safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does LNK and Jump List Forensics use?

LNK and Jump List Forensics is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does LNK and Jump List Forensics use?

About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.3k tokens, read only when the agent opens those files.

What are the alternatives to LNK and Jump List Forensics?

Skills that share tags, products or a category with LNK and Jump List Forensics: Auditing Python Dependencies (jeremylongshore/tons-of-skills-marketplace, 2.8k stars), Re Mobile Forensics (dslsdzc/rev-skills, 135 stars), Security Auditor (eigent-ai/eigent, 15k stars) and CodeQL Security Scan (trailofbits/skills, 7.5k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains LNK and Jump List Forensics?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 34,116 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.