Read-only Windows forensic scanner for software traces — persistence, execution artifacts (Prefetch, Shimcache, BAM), user activity and Ghost Tasks correlation. 20+ modules mapped to MITRE ATT&CK.
windows csharp dotnet persistence incident-response prefetch forensics dfir threat-hunting forensic-analysis blue-team mitre-attack artifact-collection shimcache
-
Updated
Jul 24, 2026 - C#