EricZimmermanCommandLineToolsCheatSheet-v1 0
EricZimmermanCommandLineToolsCheatSheet-v1 0
Common functionality Use -i to generate a list of associated program/file This cheat sheet covers the basics of using several
entries command line programs by Eric Zimmerman.
Most tools have common options for exporting data,
displaying higher precision timestamps, using custom This sheet is split into these sections:
Download location
date formats, etc. • Lnk files with LECmd
Individual tools are available at • Prefetch files with PECmd
When --mp is used, higher precision timestamps are
https://ericzimmerman.github.io/. • Jumplists with JLECmd
displayed and will also be reflected in any exported • String searching with bstrings
data. • Shimcache with AppCompatCacheParser
Chocolatey packages for each are also available.
• Amcache.hve with AmcacheParser
Data can be exported to several formats such as csv,
To get all tools at once, use chocolatey to install the
json, HTML, etc. at the same time.
EricZimmermanTools package
PECmd.exe -d <directory> --csv c:\temp --html
c:\temp\html
IT’S TIME TO GO HUNTING!
Lnk files with LECmd Jump lists with JLECmd String searching with bstrings
Type of artifact: Document creation and opening Type of artifact: Document creation and opening Type of artifact: Any