← All cheat sheets

ERIC ZIMMERMAN TOOLS (EZTOOLS)

Plain-text reference · 5 KB. Read it, search it (Ctrl-F) or print it.

Windows forensics tool suite by Eric Zimmerman. Parse and analyze
Prefetch, MFT, registry, shellbags, LNK files, event logs, and more.

DOWNLOAD#

# All tools: https://ericzimmerman.github.io/#!index.md
# Or use the downloader:
# Get-ZimmermanTools.ps1
.\Get-ZimmermanTools.ps1 -Dest C:\Tools\EZTools

TIMELINE EXPLORER#

# GUI tool for viewing CSV/TSV output from all other tools
TimelineExplorer.exe output.csv

MFTECmd (MFT PARSER)#

# Parse $MFT
MFTECmd.exe -f C:\path\to\$MFT --csv C:\output\ --csvf mft.csv

# Parse $J (USN Journal)
MFTECmd.exe -f C:\path\to\$J --csv C:\output\ --csvf usn.csv

# Parse $SDS (Security Descriptors)
MFTECmd.exe -f C:\path\to\$SDS --csv C:\output\

PECmd (PREFETCH PARSER)#

# Single prefetch file
PECmd.exe -f C:\Windows\Prefetch\CMD.EXE-*.pf --csv C:\output\

# All prefetch files
PECmd.exe -d C:\Windows\Prefetch\ --csv C:\output\ --csvf prefetch.csv

# Key info: execution times, run count, files/dirs accessed

LECmd (LNK FILE PARSER)#

# Single LNK file
LECmd.exe -f C:\path\to\file.lnk --csv C:\output\

# Directory of LNK files
LECmd.exe -d "C:\Users\*\AppData\Roaming\Microsoft\Windows\Recent" --csv C:\output\ --csvf lnk.csv

# Key info: target path, timestamps, volume info, MAC addresses

SHELLBAGS EXPLORER#

# GUI: ShellBagsExplorer.exe
# CLI: SBECmd.exe
SBECmd.exe -d C:\path\to\registry\hives --csv C:\output\ --csvf shellbags.csv

# Registry hives needed:
# USRCLASS.DAT (HKCU\Software\Classes)
# NTUSER.DAT (HKCU)

# Key info: folder access history, timestamps, even deleted folders

REGISTRY EXPLORER / RECmd#

# GUI: RegistryExplorer.exe (interactive registry hive viewer)

# CLI batch processing
RECmd.exe --bn BatchExamples\AllRegExecutablesFoundOrRun.reb -d C:\path\to\hives --csv C:\output\

# Common hives:
# SYSTEM, SAM, SECURITY, SOFTWARE, NTUSER.DAT, USRCLASS.DAT, Amcache.hve

# Key RECmd batch files:
AllRegExecutablesFoundOrRun.reb              # All executed programs
BasicSystemInfo.reb                          # OS info, computer name
InstalledSoftware.reb                        # Installed programs
NetworkInfo.reb                              # Network configuration
UserAssist.reb                               # UserAssist entries
RECmd_Batch_MC.reb                           # Mike Cary's comprehensive batch

AMCACHE PARSER#

AmcacheParser.exe -f C:\path\to\Amcache.hve --csv C:\output\ --csvf amcache.csv
# Key info: program execution, SHA1 hashes, installation timestamps

APPCOMPATCACHE PARSER#

AppCompatCacheParser.exe -f C:\path\to\SYSTEM --csv C:\output\ --csvf shimcache.csv
# Key info: executable paths, last modified times, execution flags

EVTXECMD (EVENT LOG PARSER)#

# Parse single EVTX
EvtxECmd.exe -f Security.evtx --csv C:\output\ --csvf security.csv

# Parse directory of EVTX files
EvtxECmd.exe -d C:\Windows\System32\winevt\Logs\ --csv C:\output\ --csvf allevents.csv

# With maps (enriched output)
EvtxECmd.exe -d C:\evtx\ --csv C:\output\ --maps C:\path\to\Maps\

JUMPLIST PARSER#

JLECmd.exe -d "C:\Users\*\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations" --csv C:\output\ --csvf jumplist.csv
# Key info: recently accessed files per application

SUMECMD (SRUM PARSER)#

SrumECmd.exe -f C:\path\to\SRUDB.dat -r C:\path\to\SOFTWARE --csv C:\output\
# Key info: application usage, network usage, energy usage per app

WXTCMD (WINDOWS TIMELINE)#

WxTCmd.exe -f C:\Users\user\AppData\Local\ConnectedDevicesPlatform\*\ActivitiesCache.db --csv C:\output\
# Key info: user activity timeline, app usage, file access

RBCMD (RECYCLE BIN)#

RBCmd.exe -d "C:\$Recycle.Bin" --csv C:\output\ --csvf recyclebin.csv
# Key info: deleted file paths, timestamps, sizes

INVESTIGATION WORKFLOW#

# 1. Collect artifacts (KAPE or manual)
# 2. Parse with EZTools:

# Execution evidence
PECmd.exe -d Prefetch/ --csv output/         # Prefetch
AmcacheParser.exe -f Amcache.hve --csv output/  # Amcache
AppCompatCacheParser.exe -f SYSTEM --csv output/ # Shimcache

# File access
LECmd.exe -d Recent/ --csv output/           # LNK files
JLECmd.exe -d AutomaticDestinations/ --csv output/  # Jumplists

# User activity
SBECmd.exe -d hives/ --csv output/           # Shellbags
RECmd.exe --bn UserAssist.reb -d hives/ --csv output/  # UserAssist

# System events
EvtxECmd.exe -d Logs/ --csv output/          # Event logs

# 3. Open all CSVs in Timeline Explorer
# 4. Sort by timestamp for unified timeline
# 5. Correlate across artifacts

TIPS#

  - Timeline Explorer is essential — open ALL CSVs together
  - Sort by timestamp for chronological investigation
  - KAPE collects artifacts; EZTools parses them
  - Prefetch shows execution up to 8 times with timestamps
  - Shellbags persist even after folder deletion
  - Amcache provides SHA1 hashes for IOC matching
  - LNK files prove file access from specific user context
  - RECmd batch files process multiple registry keys at once
  - USN Journal shows file system changes over time
  - All tools output to CSV for easy correlation

Defensive reference on CyberRamen. Offensive / red-team sheets live on OffensiveRamen.com.