ERIC ZIMMERMAN TOOLS (EZTOOLS)
Windows forensics tool suite by Eric Zimmerman. Parse and analyze Prefetch, MFT, registry, shellbags, LNK files, event logs, and more.
DOWNLOAD#
# All tools: https://ericzimmerman.github.io/#!index.md # Or use the downloader: # Get-ZimmermanTools.ps1 .\Get-ZimmermanTools.ps1 -Dest C:\Tools\EZTools
TIMELINE EXPLORER#
# GUI tool for viewing CSV/TSV output from all other tools TimelineExplorer.exe output.csv
MFTECmd (MFT PARSER)#
# Parse $MFT MFTECmd.exe -f C:\path\to\$MFT --csv C:\output\ --csvf mft.csv # Parse $J (USN Journal) MFTECmd.exe -f C:\path\to\$J --csv C:\output\ --csvf usn.csv # Parse $SDS (Security Descriptors) MFTECmd.exe -f C:\path\to\$SDS --csv C:\output\
PECmd (PREFETCH PARSER)#
# Single prefetch file PECmd.exe -f C:\Windows\Prefetch\CMD.EXE-*.pf --csv C:\output\ # All prefetch files PECmd.exe -d C:\Windows\Prefetch\ --csv C:\output\ --csvf prefetch.csv # Key info: execution times, run count, files/dirs accessed
LECmd (LNK FILE PARSER)#
# Single LNK file LECmd.exe -f C:\path\to\file.lnk --csv C:\output\ # Directory of LNK files LECmd.exe -d "C:\Users\*\AppData\Roaming\Microsoft\Windows\Recent" --csv C:\output\ --csvf lnk.csv # Key info: target path, timestamps, volume info, MAC addresses
SHELLBAGS EXPLORER#
# GUI: ShellBagsExplorer.exe # CLI: SBECmd.exe SBECmd.exe -d C:\path\to\registry\hives --csv C:\output\ --csvf shellbags.csv # Registry hives needed: # USRCLASS.DAT (HKCU\Software\Classes) # NTUSER.DAT (HKCU) # Key info: folder access history, timestamps, even deleted folders
REGISTRY EXPLORER / RECmd#
# GUI: RegistryExplorer.exe (interactive registry hive viewer) # CLI batch processing RECmd.exe --bn BatchExamples\AllRegExecutablesFoundOrRun.reb -d C:\path\to\hives --csv C:\output\ # Common hives: # SYSTEM, SAM, SECURITY, SOFTWARE, NTUSER.DAT, USRCLASS.DAT, Amcache.hve # Key RECmd batch files: AllRegExecutablesFoundOrRun.reb # All executed programs BasicSystemInfo.reb # OS info, computer name InstalledSoftware.reb # Installed programs NetworkInfo.reb # Network configuration UserAssist.reb # UserAssist entries RECmd_Batch_MC.reb # Mike Cary's comprehensive batch
AMCACHE PARSER#
AmcacheParser.exe -f C:\path\to\Amcache.hve --csv C:\output\ --csvf amcache.csv # Key info: program execution, SHA1 hashes, installation timestamps
APPCOMPATCACHE PARSER#
AppCompatCacheParser.exe -f C:\path\to\SYSTEM --csv C:\output\ --csvf shimcache.csv # Key info: executable paths, last modified times, execution flags
EVTXECMD (EVENT LOG PARSER)#
# Parse single EVTX EvtxECmd.exe -f Security.evtx --csv C:\output\ --csvf security.csv # Parse directory of EVTX files EvtxECmd.exe -d C:\Windows\System32\winevt\Logs\ --csv C:\output\ --csvf allevents.csv # With maps (enriched output) EvtxECmd.exe -d C:\evtx\ --csv C:\output\ --maps C:\path\to\Maps\
JUMPLIST PARSER#
JLECmd.exe -d "C:\Users\*\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations" --csv C:\output\ --csvf jumplist.csv # Key info: recently accessed files per application
SUMECMD (SRUM PARSER)#
SrumECmd.exe -f C:\path\to\SRUDB.dat -r C:\path\to\SOFTWARE --csv C:\output\ # Key info: application usage, network usage, energy usage per app
WXTCMD (WINDOWS TIMELINE)#
WxTCmd.exe -f C:\Users\user\AppData\Local\ConnectedDevicesPlatform\*\ActivitiesCache.db --csv C:\output\ # Key info: user activity timeline, app usage, file access
RBCMD (RECYCLE BIN)#
RBCmd.exe -d "C:\$Recycle.Bin" --csv C:\output\ --csvf recyclebin.csv # Key info: deleted file paths, timestamps, sizes
INVESTIGATION WORKFLOW#
# 1. Collect artifacts (KAPE or manual) # 2. Parse with EZTools: # Execution evidence PECmd.exe -d Prefetch/ --csv output/ # Prefetch AmcacheParser.exe -f Amcache.hve --csv output/ # Amcache AppCompatCacheParser.exe -f SYSTEM --csv output/ # Shimcache # File access LECmd.exe -d Recent/ --csv output/ # LNK files JLECmd.exe -d AutomaticDestinations/ --csv output/ # Jumplists # User activity SBECmd.exe -d hives/ --csv output/ # Shellbags RECmd.exe --bn UserAssist.reb -d hives/ --csv output/ # UserAssist # System events EvtxECmd.exe -d Logs/ --csv output/ # Event logs # 3. Open all CSVs in Timeline Explorer # 4. Sort by timestamp for unified timeline # 5. Correlate across artifacts
TIPS#
- Timeline Explorer is essential — open ALL CSVs together - Sort by timestamp for chronological investigation - KAPE collects artifacts; EZTools parses them - Prefetch shows execution up to 8 times with timestamps - Shellbags persist even after folder deletion - Amcache provides SHA1 hashes for IOC matching - LNK files prove file access from specific user context - RECmd batch files process multiple registry keys at once - USN Journal shows file system changes over time - All tools output to CSV for easy correlation
ERIC ZIMMERMAN TOOLS (EZTOOLS) CHEATSHEET ============================================ Source: https://cheatsheet.johlem.net Windows forensics tool suite by Eric Zimmerman. Parse and analyze Prefetch, MFT, registry, shellbags, LNK files, event logs, and more. DOWNLOAD --------- # All tools: https://ericzimmerman.github.io/#!index.md # Or use the downloader: # Get-ZimmermanTools.ps1 .\Get-ZimmermanTools.ps1 -Dest C:\Tools\EZTools TIMELINE EXPLORER ------------------- # GUI tool for viewing CSV/TSV output from all other tools TimelineExplorer.exe output.csv MFTECmd (MFT PARSER) ----------------------- # Parse $MFT MFTECmd.exe -f C:\path\to\$MFT --csv C:\output\ --csvf mft.csv # Parse $J (USN Journal) MFTECmd.exe -f C:\path\to\$J --csv C:\output\ --csvf usn.csv # Parse $SDS (Security Descriptors) MFTECmd.exe -f C:\path\to\$SDS --csv C:\output\ PECmd (PREFETCH PARSER) ------------------------- # Single prefetch file PECmd.exe -f C:\Windows\Prefetch\CMD.EXE-*.pf --csv C:\output\ # All prefetch files PECmd.exe -d C:\Windows\Prefetch\ --csv C:\output\ --csvf prefetch.csv # Key info: execution times, run count, files/dirs accessed LECmd (LNK FILE PARSER) -------------------------- # Single LNK file LECmd.exe -f C:\path\to\file.lnk --csv C:\output\ # Directory of LNK files LECmd.exe -d "C:\Users\*\AppData\Roaming\Microsoft\Windows\Recent" --csv C:\output\ --csvf lnk.csv # Key info: target path, timestamps, volume info, MAC addresses SHELLBAGS EXPLORER --------------------- # GUI: ShellBagsExplorer.exe # CLI: SBECmd.exe SBECmd.exe -d C:\path\to\registry\hives --csv C:\output\ --csvf shellbags.csv # Registry hives needed: # USRCLASS.DAT (HKCU\Software\Classes) # NTUSER.DAT (HKCU) # Key info: folder access history, timestamps, even deleted folders REGISTRY EXPLORER / RECmd --------------------------- # GUI: RegistryExplorer.exe (interactive registry hive viewer) # CLI batch processing RECmd.exe --bn BatchExamples\AllRegExecutablesFoundOrRun.reb -d C:\path\to\hives --csv C:\output\ # Common hives: # SYSTEM, SAM, SECURITY, SOFTWARE, NTUSER.DAT, USRCLASS.DAT, Amcache.hve # Key RECmd batch files: AllRegExecutablesFoundOrRun.reb # All executed programs BasicSystemInfo.reb # OS info, computer name InstalledSoftware.reb # Installed programs NetworkInfo.reb # Network configuration UserAssist.reb # UserAssist entries RECmd_Batch_MC.reb # Mike Cary's comprehensive batch AMCACHE PARSER ---------------- AmcacheParser.exe -f C:\path\to\Amcache.hve --csv C:\output\ --csvf amcache.csv # Key info: program execution, SHA1 hashes, installation timestamps APPCOMPATCACHE PARSER ----------------------- AppCompatCacheParser.exe -f C:\path\to\SYSTEM --csv C:\output\ --csvf shimcache.csv # Key info: executable paths, last modified times, execution flags EVTXECMD (EVENT LOG PARSER) ------------------------------ # Parse single EVTX EvtxECmd.exe -f Security.evtx --csv C:\output\ --csvf security.csv # Parse directory of EVTX files EvtxECmd.exe -d C:\Windows\System32\winevt\Logs\ --csv C:\output\ --csvf allevents.csv # With maps (enriched output) EvtxECmd.exe -d C:\evtx\ --csv C:\output\ --maps C:\path\to\Maps\ JUMPLIST PARSER ----------------- JLECmd.exe -d "C:\Users\*\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations" --csv C:\output\ --csvf jumplist.csv # Key info: recently accessed files per application SUMECMD (SRUM PARSER) ----------------------- SrumECmd.exe -f C:\path\to\SRUDB.dat -r C:\path\to\SOFTWARE --csv C:\output\ # Key info: application usage, network usage, energy usage per app WXTCMD (WINDOWS TIMELINE) ---------------------------- WxTCmd.exe -f C:\Users\user\AppData\Local\ConnectedDevicesPlatform\*\ActivitiesCache.db --csv C:\output\ # Key info: user activity timeline, app usage, file access RBCMD (RECYCLE BIN) --------------------- RBCmd.exe -d "C:\$Recycle.Bin" --csv C:\output\ --csvf recyclebin.csv # Key info: deleted file paths, timestamps, sizes INVESTIGATION WORKFLOW ------------------------ # 1. Collect artifacts (KAPE or manual) # 2. Parse with EZTools: # Execution evidence PECmd.exe -d Prefetch/ --csv output/ # Prefetch AmcacheParser.exe -f Amcache.hve --csv output/ # Amcache AppCompatCacheParser.exe -f SYSTEM --csv output/ # Shimcache # File access LECmd.exe -d Recent/ --csv output/ # LNK files JLECmd.exe -d AutomaticDestinations/ --csv output/ # Jumplists # User activity SBECmd.exe -d hives/ --csv output/ # Shellbags RECmd.exe --bn UserAssist.reb -d hives/ --csv output/ # UserAssist # System events EvtxECmd.exe -d Logs/ --csv output/ # Event logs # 3. Open all CSVs in Timeline Explorer # 4. Sort by timestamp for unified timeline # 5. Correlate across artifacts TIPS ----- - Timeline Explorer is essential — open ALL CSVs together - Sort by timestamp for chronological investigation - KAPE collects artifacts; EZTools parses them - Prefetch shows execution up to 8 times with timestamps - Shellbags persist even after folder deletion - Amcache provides SHA1 hashes for IOC matching - LNK files prove file access from specific user context - RECmd batch files process multiple registry keys at once - USN Journal shows file system changes over time - All tools output to CSV for easy correlation
Defensive reference on CyberRamen. Offensive / red-team sheets live on OffensiveRamen.com.