Agent skill

Parsing Artifacts With Eric Zimmerman Tools

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Parse Windows forensic artifacts—$MFT/$J (MFTECmd), Prefetch (PECmd), registry hives (RECmd), shellbags, and Amcache—into normalized CSV/JSON with Eric Zimmerman's EZ Tools, then load results into…

Apache-2.0Auto-check passedDevOps & Cloud

Install Parsing Artifacts With Eric Zimmerman Tools

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill parsing-artifacts-with-eric-zimmerman-tools -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills parsing-artifacts-with-eric-zimmerman-tools --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/parsing-artifacts-with-eric-zimmerman-tools .claude/skills/parsing-artifacts-with-eric-zimmerman-tools && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
parsing-artifacts-with-eric-zimmerman-tools
GitHub stars
34k
Token cost
~2k tokens
SKILL.md length
689 words
Files
5 (incl. scripts, references)
Skills in repo
644
Repo updated
First seen
Licence
Apache-2.0

At a glance

Parse Windows forensic artifacts—$MFT/$J (MFTECmd), Prefetch (PECmd), registry hives (RECmd), shellbags, and Amcache—into normalized CSV/JSON with Eric Zimmerman's EZ Tools, then load results into…

  • Works in 9 steps: Download/update the tools → Parse the MFT for file-system activity → Parse Prefetch for execution evidence → …
  • Tasks that involve CSV and tabular files
  • SKILL.md covers Overview, When to Use, Prerequisites and Objectives, plus 5 more sections
  • Runs Python scripts from its folder

What it does

Parsing Artifacts With Eric Zimmerman Tools is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Parse Windows forensic artifacts—$MFT/$J (MFTECmd), Prefetch (PECmd), registry hives (RECmd), shellbags, and Amcache—into normalized CSV/JSON with Eric Zimmerman's EZ Tools, then load results into Timeline Explorer for analysis. Use during DFIR/incident-response investigations, after triage collection (e.g. with KAPE), to establish program execution, file/folder access, and persistence evidence from acquired forensic images.

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including scripts and reference files (for example `references/api-reference.md`, `references/standards.md` and `scripts/agent.py`).

It sits in DevOps & Cloud, covering CSV and tabular files, Incident response and Digital forensics. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve CSV and tabular files
  • Tasks that involve Incident response
  • Tasks that involve Digital forensics

Example prompts

  • “/parsing-artifacts-with-eric-zimmerman-tools”

Requirements

  • Python 3

Workflow steps

9 steps, taken from the step headings in SKILL.md.

  1. Download/update the tools
  2. Parse the MFT for file-system activity
  3. Parse Prefetch for execution evidence
  4. Parse ShellBags for folder-access history
  5. Parse the registry with RECmd batch plugins
  6. Parse Amcache and ShimCache
  7. Parse LNK, Jump Lists, and EVTX
  8. Analyze in Timeline Explorer
  9. Cross-correlate

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com
    • ericzimmerman.github.io

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Parsing Artifacts With Eric Zimmerman Tools loads about 2k tokens when it runs, and up to ~2.9k if it reads all its reference files. Until then it costs about 118 tokens; SKILL.md has 689 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~118
When it runs · the whole SKILL.md, loaded when a task matches
~2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 689 words, ~2,041 tokens.

Download SKILL.mdSave it as .claude/skills/parsing-artifacts-with-eric-zimmerman-tools/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
parsing-artifacts-with-eric-zimmerman-tools
description
Parse Windows forensic artifacts—$MFT/$J (MFTECmd), Prefetch (PECmd), registry hives (RECmd), shellbags, and Amcache—into normalized CSV/JSON with Eric Zimmerman's EZ Tools, then load results into Timeline Explorer for analysis. Use during DFIR/incident-response investigations, after triage collection (e.g. with KAPE), to establish program execution, file/folder access, and persistence evidence from acquired forensic images.
domain
cybersecurity
subdomain
digital-forensics
tags
digital-forensics, eric-zimmerman, registry-forensics, prefetch, shellbags, mft, dfir, artifact-parsing
version
1.0
author
mahipal
license
Apache-2.0
nist_csf
RS.AN-03
mitre_attack
T1112

Parsing Artifacts with Eric Zimmerman Tools

Authorized Use Only: These tools parse evidence acquired from systems. Only analyze data you are authorized to handle, maintain chain of custody, and work from forensic copies rather than originals.

Overview

Eric Zimmerman's Tools (EZ Tools) are a free, open-source suite of high-fidelity Windows forensic parsers, each focused on a specific artifact class and each producing analyst-ready CSV/JSON output. They are the de facto standard for Windows artifact analysis and are what KAPE's !EZParser module invokes under the hood. Key tools include:

  • MFTECmd — parses $MFT, $J ($UsnJrnl), $Boot, $SDS, and $LogFile from NTFS volumes.
  • PECmd — parses Windows Prefetch (.pf) for evidence of program execution.
  • RECmd — registry hive parser/searcher driven by batch plugins (RECmd Batch files).
  • SBECmd — parses ShellBags (folder access history) from UsrClass.dat/NTUSER.DAT.
  • AmcacheParser — parses Amcache.hve for application execution and metadata.
  • AppCompatCacheParser — parses ShimCache (AppCompatCache) from SYSTEM hive.
  • LECmd — parses LNK shortcut files. JLECmd — parses Jump Lists. EvtxECmd — parses EVTX event logs to a normalized schema.

Output is designed to load into Timeline Explorer (also by Eric Zimmerman), a fast CSV/Excel viewer purpose-built for filtering, tagging, and pivoting across forensic CSVs. The 2025+ releases run on .NET and also work natively on Linux.

When to Use

  • After triage collection (e.g. with KAPE) when you need to parse raw artifacts into structured, searchable evidence.
  • To establish program execution, file/folder access, and persistence during incident response.
  • To build artifact-specific CSVs that feed timelines, Timesketch, or SIEM ingestion.

Prerequisites

Objectives

  • Parse the MFT, prefetch, shellbags, registry, and amcache from a collection.
  • Produce normalized CSV/JSON per artifact.
  • Load results into Timeline Explorer for analysis.
  • Establish execution and access evidence supporting the investigation.

MITRE ATT&CK Mapping

IDOfficial Technique NameRelevance to this skill
T1112Modify RegistryRECmd, AmcacheParser, and AppCompatCacheParser parse registry-resident artifacts; analysts use them to detect adversary registry modification (persistence, defense evasion) recorded in hives.

These are defensive parsers; the mapping reflects the artifact (registry) most relevant to the adversary behavior they help uncover.

Workflow

1. Download/update the tools

Keep parsers current so they handle the latest artifact formats.

powershell
.\Get-ZimmermanTools.ps1 -Dest C:\Tools\EZ
2. Parse the MFT for file-system activity

-f points at a single $MFT; --csv sets the output directory and --csvf the filename. Add --csvf for $J/UsnJrnl with -f $J.

cmd
MFTECmd.exe -f "E:\collection\C\$MFT" --csv "E:\out\mft" --csvf MFT.csv

REM Parse the USN Journal change log
MFTECmd.exe -f "E:\collection\C\$Extend\$J" --csv "E:\out\mft" --csvf UsnJrnl.csv
Show full SKILL.md (285 more words)Show less
3. Parse Prefetch for execution evidence

-d recurses a directory of .pf files. Output CSV + JSON.

cmd
PECmd.exe -d "E:\collection\C\Windows\Prefetch" --csv "E:\out\prefetch" --csvf Prefetch.csv --json "E:\out\prefetch\json"
4. Parse ShellBags for folder-access history

-d points at the directory containing the user's UsrClass.dat/NTUSER.DAT (or -f a single hive).

cmd
SBECmd.exe -d "E:\collection\C\Users\jsmith" --csv "E:\out\shellbags"
5. Parse the registry with RECmd batch plugins

RECmd is driven by batch files (--bn) that bundle plugins; the Kroll_Batch file is comprehensive. -d recurses a directory of hives.

cmd
RECmd.exe -d "E:\collection\C\Windows\System32\config" --bn "C:\Tools\EZ\RECmd\BatchExamples\Kroll_Batch.reb" --csv "E:\out\registry" --csvf Registry.csv

REM Search a single hive for a value/key
RECmd.exe -f "E:\collection\C\Users\jsmith\NTUSER.DAT" --sk "Run" --csv "E:\out\registry"
6. Parse Amcache and ShimCache
cmd
AmcacheParser.exe -f "E:\collection\C\Windows\AppCompat\Programs\Amcache.hve" --csv "E:\out\amcache" -i

AppCompatCacheParser.exe -f "E:\collection\C\Windows\System32\config\SYSTEM" --csv "E:\out\shimcache"
7. Parse LNK, Jump Lists, and EVTX
cmd
LECmd.exe -d "E:\collection\C\Users\jsmith\AppData\Roaming\Microsoft\Windows\Recent" --csv "E:\out\lnk"

JLECmd.exe -d "E:\collection\C\Users\jsmith\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations" --csv "E:\out\jumplists"

EvtxECmd.exe -d "E:\collection\C\Windows\System32\winevt\Logs" --csv "E:\out\evtx" --csvf EventLogs.csv
8. Analyze in Timeline Explorer

Open the resulting CSVs in Timeline Explorer (TimelineExplorer.exe). Use column filters, conditional formatting, and tagging to pivot on time, file path, and user. CSVs from all EZ Tools share consistent timestamp columns for cross-artifact correlation.

9. Cross-correlate

Build a working theory by correlating PECmd (execution time) with MFTECmd (file creation), Amcache/ShimCache (program presence), and ShellBags/LNK (access), all anchored on UTC timestamps.

Tools and Resources

ToolArtifact parsedLink
MFTECmd$MFT, $J, $Boot, $SDS, $LogFilehttps://github.com/EricZimmerman/MFTECmd
PECmdPrefetchhttps://github.com/EricZimmerman/PECmd
RECmdRegistry hiveshttps://github.com/EricZimmerman/RECmd
SBECmdShellBagshttps://github.com/EricZimmerman/Shellbags
AmcacheParserAmcache.hvehttps://github.com/EricZimmerman/AmcacheParser
AppCompatCacheParserShimCachehttps://github.com/EricZimmerman/AppCompatCacheParser
LECmd / JLECmdLNK / Jump Listshttps://ericzimmerman.github.io/
EvtxECmdEVTX event logshttps://github.com/EricZimmerman/evtx
Timeline ExplorerCSV analysis viewerhttps://ericzimmerman.github.io/
Get-ZimmermanToolsDownloader/updaterhttps://github.com/EricZimmerman/Get-ZimmermanTools

Common Flags

FlagMeaning
-f <file>Parse a single file
-d <dir>Recurse a directory
--csv <dir>CSV output directory
--csvf <name>CSV output filename
--json <dir>JSON output directory
--bn <file>RECmd batch (.reb) file
-iAmcacheParser: include file entries (unassociated)

Validation Criteria

  • EZ Tools downloaded/updated via Get-ZimmermanTools
  • $MFT (and $J) parsed to CSV
  • Prefetch parsed for execution evidence
  • ShellBags parsed for folder-access history
  • Registry parsed with Kroll_Batch (RECmd)
  • Amcache and ShimCache parsed
  • LNK/Jump Lists/EVTX parsed as needed
  • Output loaded and reviewed in Timeline Explorer
  • Cross-artifact correlation performed on UTC timestamps

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references) in skills/parsing-artifacts-with-eric-zimmerman-tools of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • references/api-reference.md
  • references/standards.md
  • scripts/agent.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Parsing Artifacts With Eric Zimmerman Tools next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Parsing Artifacts With Eric Zimmerman Tools compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Parsing Artifacts With Eric Zimmerman Tools this skillmukul975/Anthropic-Cybersecurity-Skills34k—~2kAutomated safety check: PassApache-2.0
Incident Responsealirezarezvani/claude-skills28k—~3.8kAutomated safety check: PassMIT
Responding To Incidentstrilwu/secskills157—~3.9kAutomated safety check: NotesMIT
Incident Responsehypnguyen1209/offensive-claude388—~2.5kAutomated safety check: PassMIT
Forensics OsqueryAgentSecOps/SecOpsAgentKit2201 repos~4.9kAutomated safety check: NotesCustom licence
Ir VelociraptorAgentSecOps/SecOpsAgentKit2201 repos~3.1kAutomated safety check: PassCustom licence

Similar skills

  • Incident Response

    alirezarezvani/claude-skills

    A skill your agent uses when a security incident has been detected or declared and needs classification, triage, escalation path determination, and forensic evidence collection.

    28k GitHub stars~3.8k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Responding To Incidents

    trilwu/secskills

    Run digital forensics and incident response — triage, evidence acquisition with chain of custody, host and cloud artifact analysis, timeline reconstruction, scoping, containment, eradication, and…

    157 GitHub stars~3.9k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check: notes
  • Incident Response

    hypnguyen1209/offensive-claude

    A skill your agent uses when responding to or forensically investigating an incident — triage acquisition (Velociraptor/KAPE), Volatility 3 memory forensics, Chainsaw/Hayabusa EVTX timelining…

    388 GitHub stars~2.5k tokensUpdated 13 days ago
    SecurityAuto-check passed
  • Forensics Osquery

    AgentSecOps/SecOpsAgentKit

    SQL-powered forensic investigation and system interrogation using osquery to query operating systems as relational databases.

    220 GitHub starsUsed in 1 repo~4.9k tokens
    SecurityAuto-check: notes
  • Ir Velociraptor

    AgentSecOps/SecOpsAgentKit

    Endpoint visibility, digital forensics, and incident response using Velociraptor Query Language (VQL) for evidence collection and threat hunting at scale.

    220 GitHub starsUsed in 1 repo~3.1k tokens
    SecurityAuto-check passed
  • Incident Response Lifecycle

    LeoYeAI/openclaw-master-skills

    Incident response process management following the NIST 800-61 lifecycle.

    2.2k GitHub stars~5k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 644 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Questions about Parsing Artifacts With Eric Zimmerman Tools

What does Parsing Artifacts With Eric Zimmerman Tools do?

Parse Windows forensic artifacts—$MFT/$J (MFTECmd), Prefetch (PECmd), registry hives (RECmd), shellbags, and Amcache—into normalized CSV/JSON with Eric Zimmerman's EZ Tools, then load results into…. Parsing Artifacts With Eric Zimmerman Tools is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Parse Windows forensic artifacts—$MFT/$J (MFTECmd), Prefetch (PECmd), registry hives (RECmd), shellbags, and Amcache—into normalized CSV/JSON with Eric Zimmerman's EZ Tools, then load results into Timeline Explorer for analysis.

When should I use Parsing Artifacts With Eric Zimmerman Tools?

Parsing Artifacts With Eric Zimmerman Tools fits situations like: tasks that involve CSV and tabular files; tasks that involve Incident response; tasks that involve Digital forensics.

How do I install Parsing Artifacts With Eric Zimmerman Tools in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill parsing-artifacts-with-eric-zimmerman-tools -a claude-code`. Or copy the skill folder (skills/parsing-artifacts-with-eric-zimmerman-tools in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/parsing-artifacts-with-eric-zimmerman-tools in your project. Claude Code loads it when a task matches its description.

How do I install Parsing Artifacts With Eric Zimmerman Tools in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill parsing-artifacts-with-eric-zimmerman-tools -a codex`. Or copy the skill folder (skills/parsing-artifacts-with-eric-zimmerman-tools in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/parsing-artifacts-with-eric-zimmerman-tools in your project. Codex loads it when a task matches its description.

Can I use Parsing Artifacts With Eric Zimmerman Tools in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill parsing-artifacts-with-eric-zimmerman-tools -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/parsing-artifacts-with-eric-zimmerman-tools, .gemini/skills/parsing-artifacts-with-eric-zimmerman-tools, .github/skills/parsing-artifacts-with-eric-zimmerman-tools and .opencode/skills/parsing-artifacts-with-eric-zimmerman-tools in your project.

What does Parsing Artifacts With Eric Zimmerman Tools need to run?

Going by SKILL.md and its folder, Parsing Artifacts With Eric Zimmerman Tools needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Parsing Artifacts With Eric Zimmerman Tools access the network?

SKILL.md names 2 domains. As links in the text: github.com and ericzimmerman.github.io. This is read from the text; nothing was executed.

Is Parsing Artifacts With Eric Zimmerman Tools safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Parsing Artifacts With Eric Zimmerman Tools use?

Parsing Artifacts With Eric Zimmerman Tools is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Parsing Artifacts With Eric Zimmerman Tools use?

About 2k tokens (SKILL.md is roughly 8.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 880 tokens, read only when the agent opens those files.

What are the alternatives to Parsing Artifacts With Eric Zimmerman Tools?

Skills that share tags, products or a category with Parsing Artifacts With Eric Zimmerman Tools: Incident Response (alirezarezvani/claude-skills, 28k stars), Responding To Incidents (trilwu/secskills, 157 stars), Incident Response (hypnguyen1209/offensive-claude, 388 stars) and Forensics Osquery (AgentSecOps/SecOpsAgentKit, 220 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Parsing Artifacts With Eric Zimmerman Tools?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 34,116 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.