Windows Server
sickn33/agentic-awesome-skills
Administer Windows Server systems. An agent skill from sickn33/agentic-awesome-skills.
Investigate a compromised or suspicious Windows host from on-disk artifacts -- triage collection, evidence of execution (Prefetch, Amcache, Shimcache, SRUM, UserAssist, BAM), the event-log…
$ npx skills add trilwu/secskills --skill investigating-windows-endpoints -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install trilwu/secskills investigating-windows-endpoints --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/secskills-defense/skills/investigating-windows-endpoints .claude/skills/investigating-windows-endpoints && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "investigating-windows-endpoints" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-defense/skills/investigating-windows-endpoints into .claude/skills/investigating-windows-endpoints/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "investigating-windows-endpoints", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/trilwu/secskills/tree/main/secskills-defense/skills/investigating-windows-endpointsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add trilwu/secskills --skill investigating-windows-endpoints -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install trilwu/secskills investigating-windows-endpoints --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/secskills-defense/skills/investigating-windows-endpoints .agents/skills/investigating-windows-endpoints && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "investigating-windows-endpoints" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-defense/skills/investigating-windows-endpoints into .agents/skills/investigating-windows-endpoints/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "investigating-windows-endpoints", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add trilwu/secskills --skill investigating-windows-endpoints -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install trilwu/secskills investigating-windows-endpoints --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/secskills-defense/skills/investigating-windows-endpoints .cursor/skills/investigating-windows-endpoints && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "investigating-windows-endpoints" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-defense/skills/investigating-windows-endpoints into .cursor/skills/investigating-windows-endpoints/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "investigating-windows-endpoints", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/trilwu/secskills.git --path secskills-defense/skills/investigating-windows-endpoints--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add trilwu/secskills --skill investigating-windows-endpoints -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install trilwu/secskills investigating-windows-endpoints --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/secskills-defense/skills/investigating-windows-endpoints .gemini/skills/investigating-windows-endpoints && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "investigating-windows-endpoints" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-defense/skills/investigating-windows-endpoints into .gemini/skills/investigating-windows-endpoints/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "investigating-windows-endpoints", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install trilwu/secskills investigating-windows-endpointsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add trilwu/secskills --skill investigating-windows-endpoints -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .github/skills && cp -r skills-src/secskills-defense/skills/investigating-windows-endpoints .github/skills/investigating-windows-endpoints && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "investigating-windows-endpoints" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-defense/skills/investigating-windows-endpoints into .github/skills/investigating-windows-endpoints/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "investigating-windows-endpoints", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add trilwu/secskills --skill investigating-windows-endpoints -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install trilwu/secskills investigating-windows-endpoints --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/secskills-defense/skills/investigating-windows-endpoints .opencode/skills/investigating-windows-endpoints && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "investigating-windows-endpoints" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-defense/skills/investigating-windows-endpoints into .opencode/skills/investigating-windows-endpoints/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "investigating-windows-endpoints", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
investigating-windows-endpointsInvestigate a compromised or suspicious Windows host from on-disk artifacts -- triage collection, evidence of execution (Prefetch, Amcache, Shimcache, SRUM, UserAssist, BAM), the event-log…
Investigating Windows Endpoints is an agent skill from trilwu/secskills. Investigate a compromised or suspicious Windows host from on-disk artifacts -- triage collection, evidence of execution (Prefetch, Amcache, Shimcache, SRUM, UserAssist, BAM), the event-log workhorses by ID (Security 4624/4688/4720/7045/1102, Sysmon, PowerShell 4104, RDP, WMI), persistence hunting across every autostart, lateral-movement traces, $MFT/USN filesystem forensics, anti-forensics detection, and building a super-timeline with the Eric Zimmerman suite, Chainsaw, Hayabusa, and Plaso. Use when triaging a…
Its SKILL.md is about 4.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Red teaming and adversary simulation. It works with PowerShell. The repository describes itself as: Transform Claude Code into your personal security engineer. The licence is MIT.
Read from SKILL.md and the folder at commit ca53957. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are cmd and bash).
From the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
ericzimmerman.github.ioFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Investigating Windows Endpoints loads about 4.7k tokens when it runs. Until then it costs about 190 tokens; SKILL.md has 1,729 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from trilwu/secskills at commit ca53957, republished under its MIT licence (© trilwu). 1,729 words, ~4,687 tokens.
.claude/skills/investigating-windows-endpoints/SKILL.md (or your agent's skills folder).Windows records execution, persistence, and access in dozens of artifacts the attacker rarely cleans completely. The event logs are only the surface -- the registry, prefetch, amcache, and the file-system journals corroborate or contradict them. The investigation is cross-referencing independent artifacts into one timeline that no single cleared log can defeat.
analyzing-linux-persistenceresponding-to-incidents; come here when one Windows host is the focusanalyzing-memory-images; come
here for the on-disk artifactsinvestigating-m365-entrahunting-threatsescalating-windows-privilegesDo not analyze the live disk in place. Collect a triage set, hash it, and work on the copy. For most incidents a targeted triage collection answers the question faster than a full image; image only the hosts that matter.
Dead vs. live acquisition. A powered-off host or a mounted disk image is a
dead acquisition -- consistent, but you lose running processes, network state,
and unflushed logs. A live host lets you capture volatile state (memory,
netstat -anob, Get-NetTCPConnection, tasklist /svc) but every action
mutates the disk; record what you touch. Capture memory first if the host is
live and "are they still here" is open, then hand it to analyzing-memory-images.
:: KAPE targeted triage -- the fastest way to a defensible artifact set
kape.exe --tsource C: --target !SANS_Triage --tdest E:\out\host01 --vhdx host01
:: Broader coverage: registry hives, event logs, $MFT/$J, browser, prefetch
kape.exe --tsource C: --target KapeTriage,RegistryHives,EventLogs,FileSystem ^
--tdest E:\out\host01
:: Then run the parsers (Modules) over what you collected
kape.exe --msource E:\out\host01 --mdest E:\out\host01\parsed ^
--module !EZParserVelociraptor (Windows.KapeFiles.Targets) collects the same set at fleet scale
over an agent. Whatever the tool, verify hashes before and after every copy.
Key artifact directories to make sure your collection contains:
C:\Windows\System32\winevt\Logs\ Event logs (.evtx)
C:\Windows\System32\config\ Registry hives: SYSTEM, SOFTWARE, SAM, SECURITY
C:\Users\<u>\NTUSER.DAT Per-user registry hive
C:\Users\<u>\AppData\Local\Microsoft\Windows\UsrClass.dat Shellbags, COM
C:\Windows\Prefetch\ *.pf execution evidence
C:\Windows\appcompat\Programs\Amcache.hve Amcache
C:\Windows\System32\sru\SRUDB.dat SRUM
C:\Windows\System32\Tasks\ Scheduled task XML
C:\$MFT C:\$Extend\$UsnJrnl C:\$LogFile Filesystem journals
C:\$Recycle.Bin\ Deleted-file $I recordsMultiple independent artifacts record that a binary ran. Cross-reference them -- agreement raises confidence, disagreement is itself a finding.
:: Prefetch -- run count, first/last run, files/dirs the binary touched.
:: Absent on most Servers; disabled on SSD-only systems -- note that, don't assume.
PECmd.exe -d C:\Windows\Prefetch --csv E:\out\parsed -q
:: Amcache -- SHA-1 of executed/present binaries, compile times, driver load
AmcacheParser.exe -f C:\Windows\appcompat\Programs\Amcache.hve ^
--csv E:\out\parsed -i
:: Shimcache / AppCompatCache (SYSTEM hive) -- path + last-modified; presence
:: means the file was seen, NOT necessarily executed. Order is roughly LRU.
AppCompatCacheParser.exe -f C:\Windows\System32\config\SYSTEM --csv E:\out\parsed
:: SRUM -- per-process bytes sent/received and CPU over 30-60 days.
:: Ties an executable to network volume even when netflow is gone.
SrumECmd.exe -f C:\Windows\System32\sru\SRUDB.dat ^
-r C:\Windows\System32\config\SOFTWARE --csv E:\out\parsedFrom the user (NTUSER.DAT / UsrClass.dat) hives, parse GUI-execution and
file-access evidence with RECmd:
:: UserAssist (GUI program launches, run count, focus time),
:: BAM/DAM (background/desktop activity moderator: last-run per exe per SID),
:: RecentDocs, and RunMRU in one pass with the bundled batch file
RECmd.exe -d C:\Users --bn BatchExamples\UserActivity.reb --csv E:\out\parsed...\Recent\AutomaticDestinations\*.automaticDestinations-ms)
and LNK files (...\Recent\*.lnk) record opened files/apps with target
path, volume serial, and MAC times -- parse with JLECmd and LECmd.Parse EVTX first with a triage engine (Chainsaw / Hayabusa, below), then pivot into specific channels. The IDs that carry the most weight:
Security (Security.evtx):
Sysmon (Microsoft-Windows-Sysmon/Operational), if deployed, is the
richest source:
PowerShell:
Microsoft-Windows-PowerShell/Operational) --
deobfuscated script content; hunt for -enc, FromBase64String,
DownloadString, IEX, AMSI-bypass strings. 4103 module/pipeline
logging. 400/800 in Windows PowerShell.evtx (engine start, version --
a v2 downgrade is evasion).RDP / TerminalServices:
TerminalServices-RemoteConnectionManager (auth succeeded -- user + source
IP). 21/22/25 in TerminalServices-LocalSessionManager (logon,
shell start, reconnect).WMI (Microsoft-Windows-WMI-Activity/Operational): 5857 provider
loaded, 5858 operation error, 5859-5861 permanent event-subscription
registration -- WMI persistence.
Task Scheduler (Microsoft-Windows-TaskScheduler/Operational): 106
task registered, 140 updated, 141 deleted, 200/201 action
executed/completed -- corroborates Security 4698.
Sweep every autostart, not the handful your tool checks by default. This is the
defensive mirror of establishing-persistence -- read that skill for how each
mechanism is planted, then hunt for the traces here.
...\Software\Microsoft\Windows\CurrentVersion\Run and
RunOnce, per SOFTWARE and each NTUSER.DAT; also ...\Policies\Explorer\Run....\Services; correlate installs with 7045.C:\Windows\System32\Tasks\ XML (parse the Actions
and Triggers); correlate 4698 / TaskScheduler 106.__EventFilter, __EventConsumer,
__FilterToConsumerBinding in the OBJECTS.DATA repository;
Get-WMIObject -Namespace root\subscription -Class __EventConsumer....\Start Menu\Programs\Startup\ (per-user and
All Users).Shell, Userinit, Notify under
...\Winlogon; anything appended after explorer.exe / userinit.exe.Image File Execution Options\<exe>\Debugger (and
GlobalFlag + Silent Process Exit) hijacking a legit binary.Software\Classes\CLSID\...\InprocServer32
shadowing a HKLM CLSID....\Lsa\Security Packages and Notification Packages;
...\Lsa\OSConfig.bitsadmin /list /allusers /verbose or parse
...\Microsoft\Network\Downloader\qmgr*.dat for download-and-execute jobs.:: Autoruns from Sysinternals, offline against a mounted image, VirusTotal + verify
autorunsc.exe -accepteula -a * -h -s -c -o autoruns.csv "\\?\E:\mount"
:: RECmd has batch files that dump every autostart location from the hives
RECmd.exe -d E:\out\host01 --bn BatchExamples\RegistryASEPs.reb --csv E:\out\parsedMovement leaves paired artifacts on source and destination. Correlate by time, account, and source IP.
runas /netonly.PSEXESVC-style name) plus 7036 start on the destination; 5145 if
detailed file-share auditing logged the \ADMIN$\<svc>.exe write. RemCom and
similar clones follow the same 7045+7036 pattern.wmiprvse.exe spawning a
child in Sysmon 1; WinRM over 5985/5986 (HTTP/HTTPS), with
Microsoft-Windows-WinRM/Operational and 4624 Type 3.C$, ADMIN$, IPC$ in 5140/5145;
correlate with the tool written to ADMIN$.$MFT entries for tools dropped to
the destination.The NTFS metadata files are the ground truth the attacker is least likely to scrub, and the timestomp check that no cleared log defeats.
:: $MFT -- every file's four SI + four FN timestamps, parent, size, resident data
MFTECmd.exe -f "E:\out\host01\$MFT" --csv E:\out\parsed
:: USN change journal -- creates/deletes/renames even after the file is gone
MFTECmd.exe -f "E:\out\host01\$Extend\$J" --csv E:\out\parsed
:: $LogFile -- transactional, can recover changes the USN rolled past$STANDARD_INFORMATION times are settable from
user land (SetFileTime, timestomp); $FILE_NAME times are set only by the
kernel on rename/move. SI earlier than FN, sub-second zeros on SI, or SI
disagreeing with the USN entry all flag forgery. Parse both from MFTECmd and
diff them.$Extend\$UsnJrnl:$J) records the filename, reason
(FileCreate, RenameNew, FileDelete), and USN for changes -- reconstructs
drop, rename, and cleanup of tooling even after deletion.$I files in C:\$Recycle.Bin\<SID>\ hold the original
path, size, and deletion time of each $R file (RBCmd.exe).SBECmd.exe -d E:\out\host01 --csv E:\out\parsed.dir /r, Get-Item -Stream *;
Zone.Identifier marks downloaded files (mark-of-the-web) and named streams
hide payloads.History (SQLite,
...\User Data\Default\History), Firefox places.sqlite; the downloads
table plus Zone.Identifier ADS establish what was pulled onto the host....\Terminal Server Client\Cache\*.bmc) can
reconstruct what an interactive intruder saw.Cleanup is signal, not silence. Hunt the traces of it:
...\Memory Management\PrefetchParameters\EnablePrefetcher = 0.fsutil usn deletejournal leaves the journal
truncated; note the missing history as a gap.State every such gap explicitly in the timeline as a limitation -- never let a cleared log become an implicit "nothing happened."
Fast triage first, then the full timeline. Normalize everything to UTC, cite the source artifact on every row, and separate observed from inferred.
:: Chainsaw -- fast EVTX triage with built-in + Sigma rules, minutes not hours
chainsaw hunt E:\out\host01\...\winevt\Logs -s sigma\ ^
--mapping mappings\sigma-event-logs-all.yml -r rules\ --csv -o chainsaw_out
:: Hayabusa -- EVTX -> single timeline scored by severity, Sigma-backed
hayabusa.exe csv-timeline -d E:\out\host01\...\winevt\Logs -o hayabusa.csv -p verbose# Plaso -- ingest the whole triage set (or image) into one storage file...
log2timeline.py --storage-file plaso.db E:\out\host01
# ...then filter and export the super-timeline
psort.py -o l2tcsv -w super.csv plaso.db "date > '2026-07-01 00:00:00'"Load the parsed CSVs (EZ Tools output, Chainsaw, psort) into Timeline
Explorer to pivot, tag, and color across artifacts in one grid. The Eric
Zimmerman suite -- PECmd, AmcacheParser, AppCompatCacheParser, SrumECmd,
MFTECmd, RECmd, SBECmd, JLECmd, LECmd, RBCmd -- plus Chainsaw / Hayabusa
for EVTX and Plaso for the union timeline is the core toolchain. Write
detections for what you find with writing-sigma-rules; hand the narrative to
reporting-security-findings.
$STANDARD_INFORMATION
is trivially forged. Check $FILE_NAME and the USN journal; disagreement is
the finding.analyzing-linux-persistence -- the same host-forensic sweep for Linuxresponding-to-incidents -- the IR process and multi-host coordination this
feedsanalyzing-memory-images -- RAM analysis for the volatile half of the hostinvestigating-m365-entra -- when the compromise is in cloud identityhunting-threats -- proactive fleet-wide hunting with no specific hostestablishing-persistence -- offensive view of the autostarts hunted herewriting-sigma-rules -- detections for the event-log patterns foundreporting-security-findings -- turning the timeline into the deliverable© trilwu, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in secskills-defense/skills/investigating-windows-endpoints of trilwu/secskills.
Open the folder on GitHubat commit ca53957
Investigating Windows Endpoints next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Investigating Windows Endpoints this skilltrilwu/secskills | 157 | — | ~4.7k | Automated safety check: Pass | MIT | |
| Windows Serversickn33/agentic-awesome-skills | 47k | 2 repos | ~2.9k | Automated safety check: Pass | MIT | |
| Performing Purple Team Atomic Testingmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~9.8k | Automated safety check: Pass | Apache-2.0 | |
| Analyzing Powershell Empire Artifactsmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~719 | Automated safety check: Pass | Apache-2.0 | |
| Hunting For Lateral Movement Via Wmimukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~659 | Automated safety check: Pass | Apache-2.0 | |
| Windows Av Evasionyaklang/hack-skills | 2.4k | — | ~2.9k | Automated safety check: Pass | MIT |
sickn33/agentic-awesome-skills
Administer Windows Server systems. An agent skill from sickn33/agentic-awesome-skills.
mukul975/Anthropic-Cybersecurity-Skills
Executes Atomic Red Team tests mapped to MITRE ATT&CK via Invoke-AtomicRedTeam PowerShell, generates ATT&CK Navigator coverage heatmaps, correlates results against Sigma rules, and runs detection…
mukul975/Anthropic-Cybersecurity-Skills
Detect PowerShell Empire post-exploitation framework artifacts in Windows Script Block Logging (Event ID 4104) and Module Logging (Event ID 4103), including the default launcher string…
mukul975/Anthropic-Cybersecurity-Skills
Detects WMI-based lateral movement (e.g. An agent skill from mukul975/Anthropic-Cybersecurity-Skills.
yaklang/hack-skills
AV/EDR evasion playbook for Windows. An agent skill from yaklang/hack-skills.
waybarrios/opencode-power-pack
Verify or select a SageMaker execution role before creating models, endpoints, or training jobs.
trilwu/secskills
Audit source code for exploitable vulnerabilities using threat-model-driven review, taint tracing, invariant checking, and variant analysis.
trilwu/secskills
Perform OSINT, subdomain enumeration, port scanning, web reconnaissance, email harvesting, and cloud asset discovery for initial access.
trilwu/secskills
Assess and harden LLM applications and agentic systems against prompt injection, tool misuse, excessive agency, memory poisoning, RAG data leakage, and model supply-chain risk, mapped to the OWASP…
trilwu/secskills
Reverse engineer compiled binaries, firmware, and mobile app packages using triage, static disassembly, decompilation, and dynamic instrumentation.
trilwu/secskills
Reverse engineer Go binaries by recovering function names and types from pclntab and moduledata using GoReSym, redress, and IDA/Ghidra Go plugins, and by reading Go's non-standard calling…
trilwu/secskills
Analyze iOS applications at the binary level — decrypting FairPlay-protected IPAs with frida-ios-dump or bagbak, inspecting Mach-O load commands, recovering Objective-C headers with class-dump, and…
Works with
Categories
Investigate a compromised or suspicious Windows host from on-disk artifacts -- triage collection, evidence of execution (Prefetch, Amcache, Shimcache, SRUM, UserAssist, BAM), the event-log…. Investigating Windows Endpoints is an agent skill from trilwu/secskills. Investigate a compromised or suspicious Windows host from on-disk artifacts -- triage collection, evidence of execution (Prefetch, Amcache, Shimcache, SRUM, UserAssist, BAM), the event-log workhorses by ID (Security 4624/4688/4720/7045/1102, Sysmon, PowerShell 4104, RDP, WMI), persistence hunting across every autostart, lateral-movement traces, $MFT/USN filesystem forensics, anti-forensics detection, and building a super-timeline with the Eric Zimmerman suite, Chainsaw, Hayabusa, and Plaso.
Investigating Windows Endpoints fits situations like: triaging a compromised; suspicious Windows host; working through EVTX/Sysmon logs; reconstructing what executed on a Windows machine.
Run `npx skills add trilwu/secskills --skill investigating-windows-endpoints -a claude-code`. Or copy the skill folder (secskills-defense/skills/investigating-windows-endpoints in trilwu/secskills) into .claude/skills/investigating-windows-endpoints in your project. Claude Code loads it when a task matches its description.
Run `npx skills add trilwu/secskills --skill investigating-windows-endpoints -a codex`. Or copy the skill folder (secskills-defense/skills/investigating-windows-endpoints in trilwu/secskills) into .agents/skills/investigating-windows-endpoints in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trilwu/secskills --skill investigating-windows-endpoints -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/investigating-windows-endpoints, .gemini/skills/investigating-windows-endpoints, .github/skills/investigating-windows-endpoints and .opencode/skills/investigating-windows-endpoints in your project.
SKILL.md names no scripts, command-line tools or credentials: Investigating Windows Endpoints is instructions for the agent only.
SKILL.md names 1 domain. As links in the text: ericzimmerman.github.io. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Investigating Windows Endpoints is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.7k tokens (SKILL.md is roughly 19k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Investigating Windows Endpoints: Windows Server (sickn33/agentic-awesome-skills, 47k stars), Performing Purple Team Atomic Testing (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Analyzing Powershell Empire Artifacts (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Hunting For Lateral Movement Via Wmi (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
trilwu (a GitHub user) maintains it in trilwu/secskills, which has 157 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on September 4, 2026.
Source: trilwu/secskills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.