Agent skill

Analyzing Windows Amcache Artifacts

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Parses the Windows Amcache.hve registry hive with Eric Zimmerman's AmcacheParser and Timeline Explorer to extract evidence of program execution, application installation, and driver loading…

Apache-2.0Auto-check passedSecurity

Install Analyzing Windows Amcache Artifacts

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill analyzing-windows-amcache-artifacts -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills analyzing-windows-amcache-artifacts --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/analyzing-windows-amcache-artifacts .claude/skills/analyzing-windows-amcache-artifacts && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
analyzing-windows-amcache-artifacts
GitHub stars
34k
Token cost
~2.8k tokens
SKILL.md length
690 words
Files
4 (incl. scripts, references)
Skills in repo
637
Repo updated
First seen
Licence
Apache-2.0

At a glance

Parses the Windows Amcache.hve registry hive with Eric Zimmerman's AmcacheParser and Timeline Explorer to extract evidence of program execution, application installation, and driver loading…

  • Works in 7 steps: Acquire the Amcache.hve File → Parse Amcache with AmcacheParser → Analyze File Entries for Suspicious… → …
  • Amcache forensics
  • SKILL.md covers When to Use, Prerequisites, Workflow and Key Concepts, plus 1 more section
  • Runs Python scripts from its folder; reaches hashlookup.circl.lu

What it does

Analyzing Windows Amcache Artifacts is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Parses the Windows Amcache.hve registry hive with Eric Zimmerman's AmcacheParser and Timeline Explorer to extract evidence of program execution, application installation, and driver loading, including SHA-1 hash correlation with threat intel and timeline reconstruction. Use for Amcache forensics, program execution evidence gathering, or application compatibility cache investigations in DFIR work.

Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/api-reference.md` and `scripts/agent.py`).

It sits in Security, covering Digital forensics. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Amcache forensics
  • Program execution evidence gathering
  • Application compatibility cache investigations in DFIR work

Example prompts

  • “Use the analyzing-windows-amcache-artifacts skill to parse the Windows Amcache.hve registry hive with Eric Zimmerman's AmcacheParser and Timeline…”
  • “/analyzing-windows-amcache-artifacts”

Requirements

  • Python 3

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Acquire the Amcache.hve File
  2. Parse Amcache with AmcacheParser
  3. Analyze File Entries for Suspicious Programs
  4. Correlate SHA-1 Hashes with Threat Intelligence
  5. Analyze Program Entries for Unauthorized Installations
  6. Analyze Driver Binaries for Rootkit Evidence
  7. Build a Timeline from Amcache Data

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • hashlookup.circl.lu

    Also links to:

    • ericzimmerman.github.io

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Analyzing Windows Amcache Artifacts loads about 2.8k tokens when it runs, and up to ~3.3k if it reads all its reference files. Until then it costs about 109 tokens; SKILL.md has 690 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~109
When it runs · the whole SKILL.md, loaded when a task matches
~2.8k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 690 words, ~2,794 tokens.

Download SKILL.mdSave it as .claude/skills/analyzing-windows-amcache-artifacts/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
analyzing-windows-amcache-artifacts
description
Parses the Windows Amcache.hve registry hive with Eric Zimmerman's AmcacheParser and Timeline Explorer to extract evidence of program execution, application installation, and driver loading, including SHA-1 hash correlation with threat intel and timeline reconstruction. Use for Amcache forensics, program execution evidence gathering, or application compatibility cache investigations in DFIR work.
domain
cybersecurity
subdomain
digital-forensics
tags
amcache, windows-forensics, program-execution, AmcacheParser, eric-zimmerman, timeline-analysis, DFIR
version
1.0.0
author
mahipal
license
Apache-2.0
nist_csf
RS.AN-03, DE.AE-02, RS.MA-01
mitre_attack
T1070.004, T1070.006, T1036.005, T1014, T1005

Analyzing Windows Amcache Artifacts

When to Use

  • Determining which programs have existed or executed on a Windows system during incident response
  • Correlating SHA-1 hashes from Amcache against known malware databases (VirusTotal, CIRCL, MISP)
  • Building an application installation and execution timeline for forensic investigations
  • Identifying deleted executables that leave traces in Amcache even after file removal
  • Investigating insider threats by documenting which portable or unauthorized applications were present
  • Analyzing driver loading history to detect rootkits or malicious kernel modules

Do not use as sole proof of program execution. Amcache proves file existence and metadata registration, but ShimCache (AppCompatCache) and Prefetch provide stronger execution evidence. Use all three artifacts together for conclusive analysis.

Prerequisites

  • A forensic image or live triage copy of C:\Windows\appcompat\Programs\Amcache.hve (and associated .LOG1, .LOG2 transaction logs)
  • Eric Zimmerman's AmcacheParser (AmcacheParser.exe) downloaded from https://ericzimmerman.github.io/
  • Eric Zimmerman's Timeline Explorer for viewing parsed CSV output
  • Optionally: Registry Explorer for manual hive inspection
  • A SHA-1 whitelist of known-good executables (e.g., NSRL hashset) for filtering
  • .NET 6+ runtime installed (required by current EZ tools)
  • Write access to an output directory for CSV results

Workflow

Step 1: Acquire the Amcache.hve File

Extract the Amcache hive from a forensic image or live system:

powershell
# From a live system (requires elevated privileges and raw copy tool)
# Amcache.hve is locked by the system; use a raw disk copy tool
# Option A: FTK Imager - mount image and navigate to:
# C:\Windows\appcompat\Programs\Amcache.hve
# Also collect: Amcache.hve.LOG1, Amcache.hve.LOG2

# Option B: Using KAPE for automated triage collection
kape.exe --tsource C: --tdest D:\Evidence\%m --target Amcache

# Option C: From a mounted forensic image (E: = mounted image)
copy "E:\Windows\appcompat\Programs\Amcache.hve" D:\Evidence\
copy "E:\Windows\appcompat\Programs\Amcache.hve.LOG1" D:\Evidence\
copy "E:\Windows\appcompat\Programs\Amcache.hve.LOG2" D:\Evidence\

Always collect the transaction log files (.LOG1, .LOG2) alongside the hive. AmcacheParser replays uncommitted transactions from these logs to recover the most complete data.

Step 2: Parse Amcache with AmcacheParser

Run AmcacheParser against the acquired hive:

powershell
# Basic parsing with CSV output
AmcacheParser.exe -f "D:\Evidence\Amcache.hve" --csv "D:\Evidence\Output"

# Parse with a SHA-1 whitelist to exclude known-good entries (NSRL)
AmcacheParser.exe -f "D:\Evidence\Amcache.hve" -w "D:\Whitelists\nsrl_sha1.txt" --csv "D:\Evidence\Output"

# Parse with a SHA-1 inclusion list (only show matches against known-bad hashes)
AmcacheParser.exe -f "D:\Evidence\Amcache.hve" -b "D:\IOCs\malware_sha1.txt" --csv "D:\Evidence\Output"

# Include deleted entries with high-precision timestamps
AmcacheParser.exe -f "D:\Evidence\Amcache.hve" --csv "D:\Evidence\Output" -i --mp

AmcacheParser produces multiple CSV files in the output directory:

Output FileContents
Amcache_AssociatedFileEntries.csvFile entries with SHA-1 hashes, paths, sizes, and timestamps
Amcache_UnassociatedFileEntries.csvOrphaned file entries from older Amcache format
Amcache_ProgramEntries.csvInstalled program metadata (name, publisher, version, install date)
Amcache_DeviceContainers.csvUSB and device connection history
Amcache_DevicePnps.csvPlug-and-Play device driver information
Amcache_DriverBinaries.csvLoaded driver binaries with paths and hashes
Step 3: Analyze File Entries for Suspicious Programs

Open the AssociatedFileEntries.csv in Timeline Explorer and examine key columns:

Key columns to review:
- ProgramId          : Links file to its parent program entry
- SHA1               : Hash for threat intel lookups
- FullPath           : Original file location on disk
- FileSize           : Size of the executable
- FileKeyLastWriteTimestamp : When the Amcache entry was last updated
- Name               : File name
- Publisher           : Code signing publisher (blank = unsigned)
- BinProductVersion  : Version string from the PE header
- LinkDate           : PE compilation timestamp (useful for detecting timestomping)

Filter for suspicious indicators:

# In Timeline Explorer, apply these filters:

# 1. Find unsigned executables (potentially malicious)
Publisher column = (empty)

# 2. Find executables from suspicious paths
FullPath contains: \temp\, \appdata\, \downloads\, \public\, \programdata\

# 3. Find executables with recent timestamps during incident window
FileKeyLastWriteTimestamp between: 2026-03-15 00:00:00 and 2026-03-16 00:00:00

# 4. Find executables with suspicious compilation dates (timestomping)
LinkDate year < 2015 AND FileKeyLastWriteTimestamp year = 2026
Step 4: Correlate SHA-1 Hashes with Threat Intelligence

Extract SHA-1 hashes and check against malware databases:

powershell
# Extract unique SHA-1 hashes from the parsed output
# Using PowerShell to extract the SHA1 column
Import-Csv "D:\Evidence\Output\Amcache_AssociatedFileEntries.csv" |
  Select-Object -ExpandProperty SHA1 -Unique |
  Where-Object { $_ -ne "" } |
  Out-File "D:\Evidence\Output\extracted_hashes.txt"

# Check hashes against VirusTotal using vt-cli
foreach ($hash in Get-Content "D:\Evidence\Output\extracted_hashes.txt") {
    vt file $hash --format json | Select-Object -Property meaningful_name, last_analysis_stats
}

# Check hashes against CIRCL hashlookup
foreach ($hash in Get-Content "D:\Evidence\Output\extracted_hashes.txt") {
    Invoke-RestMethod -Uri "https://hashlookup.circl.lu/lookup/sha1/$hash"
}

# Cross-reference with NSRL to identify known-good vs. unknown
# Unknown hashes that are not in NSRL warrant closer investigation
Step 5: Analyze Program Entries for Unauthorized Installations

Review the ProgramEntries.csv for software the attacker may have installed:

Key columns in ProgramEntries:
- ProgramName        : Display name of installed application
- ProgramVersion     : Version string
- Publisher          : Software publisher
- InstallDate        : When the program was installed
- Source             : Installation source (msi, exe, etc.)
- UninstallKey       : Registry uninstall path
- PathsList         : Installation directories

Look for:

  • Remote access tools (AnyDesk, TeamViewer, ngrok, Chisel)
  • Hacking tools (Mimikatz, PsExec, Cobalt Strike)
  • Tunneling utilities (plink, socat, WireGuard)
  • Programs installed during the incident window
  • Programs installed to non-standard locations
Step 6: Analyze Driver Binaries for Rootkit Evidence

Review the DriverBinaries.csv for suspicious loaded drivers:

Key columns in DriverBinaries:
- DriverName         : Name of the driver
- DriverInBox        : Whether it shipped with Windows (false = third-party)
- DriverSigned       : Whether the driver has a valid signature
- DriverTimeStamp    : Compilation timestamp
- Product            : Product associated with the driver
- ProductVersion     : Driver version
- SHA1               : Hash of the driver binary

Filter for DriverInBox = false and DriverSigned = false to find unsigned third-party drivers that may be rootkits or vulnerable drivers used in BYOVD (Bring Your Own Vulnerable Driver) attacks.

Show full SKILL.md (269 more words)Show less
Step 7: Build a Timeline from Amcache Data

Combine Amcache data with other artifacts for a comprehensive timeline:

powershell
# Merge Amcache CSV with other EZ Tools output using Timeline Explorer
# Load the following CSVs into Timeline Explorer:
# - Amcache_AssociatedFileEntries.csv (file evidence)
# - Amcache_ProgramEntries.csv (install evidence)
# - Prefetch output from PECmd.exe (execution evidence)
# - ShimCache output from AppCompatCacheParser.exe (execution evidence)

# Sort all entries by timestamp to reconstruct the attack sequence
# Timeline Explorer supports multi-file loading and column-based sorting

# Export the combined timeline
# File > Save to CSV > combined_timeline.csv

Key Concepts

TermDefinition
Amcache.hveA Windows registry hive at C:\Windows\appcompat\Programs\Amcache.hve that stores metadata about applications, files, and drivers for application compatibility purposes
Associated File EntryAn Amcache record linked to a specific program installation, containing file path, size, hash, and timestamps
Unassociated File EntryAn orphaned Amcache record from an older format that is not linked to a program entry; common on Windows 7/8 systems
Program EntryAmcache record containing installation metadata: program name, version, publisher, install date, and uninstall key
SHA-1 HashCryptographic hash stored in Amcache for each registered file, enabling malware identification through threat intelligence lookups
LinkDateThe PE compilation timestamp embedded in the executable header; discrepancy with file system timestamps may indicate timestomping
Transaction Logs.LOG1 and .LOG2 files containing uncommitted registry transactions that AmcacheParser replays for complete data recovery
NSRL (National Software Reference Library)NIST-maintained database of SHA-1 hashes for known commercial software, used as a whitelist to filter benign entries

Verification

  • Amcache.hve and transaction logs (LOG1, LOG2) were collected from the forensic image
  • AmcacheParser produced all expected CSV output files without errors
  • SHA-1 hashes were extracted and checked against VirusTotal or CIRCL hashlookup
  • Unsigned executables in suspicious paths have been flagged for further analysis
  • Program entries show all software installations within the incident window
  • Driver binaries have been checked for unsigned or out-of-box entries
  • LinkDate vs. FileKeyLastWriteTimestamp comparison has been performed to detect timestomping
  • Amcache findings are correlated with Prefetch and ShimCache for execution confirmation
  • Final timeline integrates Amcache data with other forensic artifacts

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts, references) in skills/analyzing-windows-amcache-artifacts of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • references/api-reference.md
  • scripts/agent.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Analyzing Windows Amcache Artifacts next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Analyzing Windows Amcache Artifacts compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Analyzing Windows Amcache Artifacts this skillmukul975/Anthropic-Cybersecurity-Skills34k—~2.8kAutomated safety check: PassApache-2.0
Ctf Malwareljagiello/ctf-skills3.4k1 repos~2.1kAutomated safety check: NotesMIT
Oss ForensicsTommy-yw/RunbookHermes5463 repos~5kAutomated safety check: PassMIT
Dfirtransilienceai/communitytools562—~1.5kAutomated safety check: PassMIT
TShark Traffic AnalysisAgentSecOps/SecOpsAgentKit2201 repos~4.8kAutomated safety check: NotesCustom licence
Runtime Memory Sample Acquisitiondslsdzc/rev-skills125—~2kAutomated safety check: PassApache-2.0

Similar skills

  • Ctf Malware

    ljagiello/ctf-skills

    Provides malware analysis and network traffic techniques for CTF challenges.

    3.4k GitHub starsUsed in 1 repo~2.1k tokens
    SecurityAuto-check: notes
  • Oss Forensics

    Tommy-yw/RunbookHermes

    Supply chain investigation, evidence recovery, and forensic analysis for GitHub repositories.

    546 GitHub starsUsed in 3 repos~5k tokens
    SecurityAuto-check passed
  • Dfir

    transilienceai/communitytools

    Digital forensics and incident response - Windows event log analysis, PCAP forensics, filesystem artifact analysis, AD attack detection, and timeline correlation.

    562 GitHub stars~1.5k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • TShark Traffic Analysis

    AgentSecOps/SecOpsAgentKit

    Guides authorized packet capture and analysis with TShark, Wireshark's command-line tool, for security investigations, malware detection and forensic examination of network traffic.

    220 GitHub starsUsed in 1 repo~4.8k tokens
    SecurityAuto-check: notes
  • Captures an analyzable sample from a live system when the target leaves no file on disk, by finding abnormal executable memory and the execution context that reached it.

    125 GitHub stars~2k tokensUpdated 3 days ago
    SecurityAuto-check passed
  • Digital Forensics

    zhaoxuya520/reverse-skill

    A skill your agent uses for authorized digital forensics including memory dumps, disk timelines, PCAP investigation, artifact triage, and IR evidence preservation.

    40k GitHub starsUsed in 2 repos~389 tokens
    SecurityAuto-check: warnings

More from mukul975/Anthropic-Cybersecurity-Skills

All 637 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Analyzing Windows Amcache Artifacts

What does Analyzing Windows Amcache Artifacts do?

Parses the Windows Amcache.hve registry hive with Eric Zimmerman's AmcacheParser and Timeline Explorer to extract evidence of program execution, application installation, and driver loading…. Analyzing Windows Amcache Artifacts is an agent skill from mukul975/Anthropic-Cybersecurity-Skills.hve registry hive with Eric Zimmerman's AmcacheParser and Timeline Explorer to extract evidence of program execution, application installation, and driver loading, including SHA-1 hash correlation with threat intel and timeline reconstruction.

When should I use Analyzing Windows Amcache Artifacts?

Analyzing Windows Amcache Artifacts fits situations like: amcache forensics; program execution evidence gathering; application compatibility cache investigations in DFIR work.

How do I install Analyzing Windows Amcache Artifacts in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill analyzing-windows-amcache-artifacts -a claude-code`. Or copy the skill folder (skills/analyzing-windows-amcache-artifacts in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/analyzing-windows-amcache-artifacts in your project. Claude Code loads it when a task matches its description.

How do I install Analyzing Windows Amcache Artifacts in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill analyzing-windows-amcache-artifacts -a codex`. Or copy the skill folder (skills/analyzing-windows-amcache-artifacts in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/analyzing-windows-amcache-artifacts in your project. Codex loads it when a task matches its description.

Can I use Analyzing Windows Amcache Artifacts in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill analyzing-windows-amcache-artifacts -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/analyzing-windows-amcache-artifacts, .gemini/skills/analyzing-windows-amcache-artifacts, .github/skills/analyzing-windows-amcache-artifacts and .opencode/skills/analyzing-windows-amcache-artifacts in your project.

What does Analyzing Windows Amcache Artifacts need to run?

Going by SKILL.md and its folder, Analyzing Windows Amcache Artifacts needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Analyzing Windows Amcache Artifacts access the network?

SKILL.md names 2 domains. In commands or code: hashlookup.circl.lu; the agent is likely to contact it when it follows the instructions. As links in the text: ericzimmerman.github.io. This is read from the text; nothing was executed.

Is Analyzing Windows Amcache Artifacts safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Analyzing Windows Amcache Artifacts use?

Analyzing Windows Amcache Artifacts is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Analyzing Windows Amcache Artifacts use?

About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 519 tokens, read only when the agent opens those files.

What are the alternatives to Analyzing Windows Amcache Artifacts?

Skills that share tags, products or a category with Analyzing Windows Amcache Artifacts: Ctf Malware (ljagiello/ctf-skills, 3.4k stars), Oss Forensics (Tommy-yw/RunbookHermes, 546 stars), Dfir (transilienceai/communitytools, 562 stars) and TShark Traffic Analysis (AgentSecOps/SecOpsAgentKit, 220 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Analyzing Windows Amcache Artifacts?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 33,922 GitHub stars. The repository holds 637 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.