Eric Zimmerman Tools Hands-on Labs¶
Choose one browser simulation for focused practice, then complete the Full Lab to correlate several Windows artefacts in an isolated, authorised environment.
PECmd Interactive Lab¶
JumpList Explorer Interactive Lab¶
Full Lab¶
Hands-on Windows artefact proof of concept
Parse it. View it. Correlate it.
After practising one parser and one viewer above, use the Full Lab to select supporting sources, preserve derived output and defend a cross-tool conclusion.
Cross-tool Windows Artefact Full Lab
Use supplied or authorised evidence
Do not collect from a system you are not authorised to examine. Protect the supplied source, work from integrity-verified copies and write parser output to separate storage.
Case
SUSA-EZ-058: determine whether remote-admin.exe was represented on
WIN11-LAB01, whether retained evidence supports likely execution, and which
user-facing activity can be correlated with it.
You need
An isolated Windows VM, current recorded EZ Tools, Timeline Explorer, the supplied evidence package, sufficient controlled storage and a case notebook.
Beginner Core Lab
Use PECmd plus one supporting parser and one GUI viewer. Answer the bounded case question and preserve a reproducible evidence trail.
Optional extension
Add the remaining supplied sources and compare how Amcache, ShimCache, Prefetch, EVTX and user artefacts represent the same activity differently.
01
Activity 1: Establish the boundary¶
- Record the case question, host, user scope, collection time and time zone.
- Inventory the supplied hives, Prefetch files, EVTX logs and user artefacts.
- Verify the package manifest and create identified working copies.
- Record every selected tool's path, version and hash.
- Create separate
source,derived,exportsandnotesdirectories.
02
Activity 2: Parse and inspect¶
- Use PECmd on the supplied Prefetch working copy and retain its command, console output, CSV and hash.
- Choose AmcacheParser or AppCompatCacheParser as a supporting parser. Explain why its source can contribute to this question before running it.
- If supplied EVTX covers the relevant interval, use EvtxECmd and filter a working CSV without discarding surrounding event context.
- Choose ShellBags Explorer or JumpList Explorer for the user-context question. Record the source file, filters, selected row and export.
- Build a short observation table that separates source record, observation, inference and limitation.
03
Activity 3: Correlate and report¶
Create a timeline using the source time zone and distinguish:
- file or path presence;
- compatibility or inventory representation;
- execution-related evidence;
- application-linked or folder-interaction context; and
- facts that remain unknown.
Write a conclusion that answers the case question, cites at least two independent artefact types and records confidence and limitations. Do not use Amcache or ShimCache alone as proof of execution, and do not convert a hash reputation result into a verdict about intent.
Full Lab evidence checklist¶
This checklist applies to the VM-based Full Lab. For either browser lab, retain the downloaded evidence summary instead.
Complete the core items first. The analyst-practice items strengthen review but do not replace missing source provenance or a bounded conclusion.
-
Core completion¶
Required to demonstrate a traceable parser, viewer and correlation workflow.
-
Good analyst practice¶
Records that make the examination easier to reproduce and challenge.
Troubleshooting¶
| Symptom | Check |
|---|---|
| Tool will not start | Confirm the documented runtime, architecture and complete release package. |
| No rows returned | Recheck source type, OS version, parser syntax, permissions and whether the artefact actually exists. |
| Times conflict | Record each source time basis and display setting before converting. |
| GUI result cannot be reproduced | Preserve the source, version, filters, sorting and exported rows, not only a screenshot. |
Clean up¶
Hash the final evidence package, close all working sources, remove temporary copies according to lab policy and revert the isolated VM snapshot. Do not delete the protected source, case notes or required derived evidence.