Skip to content

Eric Zimmerman Tools Hands-on Labs

Choose one browser simulation for focused practice, then complete the Full Lab to correlate several Windows artefacts in an isolated, authorised environment.

PECmd Interactive Lab

JumpList Explorer Interactive Lab

Full Lab

Hands-on Windows artefact proof of concept

Parse it. View it. Correlate it.

After practising one parser and one viewer above, use the Full Lab to select supporting sources, preserve derived output and defend a cross-tool conclusion.

⏱ Setup: 20–30 min · Exercise: 75–120 min◆ Guided beginner✓ Evidence required
Isolated Windows VM · 75–120 min

Cross-tool Windows Artefact Full Lab

EZ Tools, training evidence and case storage required

Use supplied or authorised evidence

Do not collect from a system you are not authorised to examine. Protect the supplied source, work from integrity-verified copies and write parser output to separate storage.

Case

SUSA-EZ-058: determine whether remote-admin.exe was represented on WIN11-LAB01, whether retained evidence supports likely execution, and which user-facing activity can be correlated with it.

You need

An isolated Windows VM, current recorded EZ Tools, Timeline Explorer, the supplied evidence package, sufficient controlled storage and a case notebook.

Optional extension

Add the remaining supplied sources and compare how Amcache, ShimCache, Prefetch, EVTX and user artefacts represent the same activity differently.

01

Activity 1: Establish the boundary

  1. Record the case question, host, user scope, collection time and time zone.
  2. Inventory the supplied hives, Prefetch files, EVTX logs and user artefacts.
  3. Verify the package manifest and create identified working copies.
  4. Record every selected tool's path, version and hash.
  5. Create separate source, derived, exports and notes directories.
Milestone 1Boundary establishedEvery source and executable is identified, integrity checked and linked to the case question.

02

Activity 2: Parse and inspect

  1. Use PECmd on the supplied Prefetch working copy and retain its command, console output, CSV and hash.
  2. Choose AmcacheParser or AppCompatCacheParser as a supporting parser. Explain why its source can contribute to this question before running it.
  3. If supplied EVTX covers the relevant interval, use EvtxECmd and filter a working CSV without discarding surrounding event context.
  4. Choose ShellBags Explorer or JumpList Explorer for the user-context question. Record the source file, filters, selected row and export.
  5. Build a short observation table that separates source record, observation, inference and limitation.
Milestone 2Outputs remain traceableAnother analyst can reproduce every parser and viewer observation from the retained working sources.

03

Activity 3: Correlate and report

Create a timeline using the source time zone and distinguish:

  • file or path presence;
  • compatibility or inventory representation;
  • execution-related evidence;
  • application-linked or folder-interaction context; and
  • facts that remain unknown.

Write a conclusion that answers the case question, cites at least two independent artefact types and records confidence and limitations. Do not use Amcache or ShimCache alone as proof of execution, and do not convert a hash reputation result into a verdict about intent.

Milestone 3Conclusion is defensibleThe report links every claim to a source and clearly identifies what requires further corroboration.

Full Lab evidence checklist

This checklist applies to the VM-based Full Lab. For either browser lab, retain the downloaded evidence summary instead.

Complete the core items first. The analyst-practice items strengthen review but do not replace missing source provenance or a bounded conclusion.

  • Core completion

    Required to demonstrate a traceable parser, viewer and correlation workflow.

  • Good analyst practice

    Records that make the examination easier to reproduce and challenge.

0 of 8 recorded Mark each item after saving the evidence.

Troubleshooting

Symptom Check
Tool will not start Confirm the documented runtime, architecture and complete release package.
No rows returned Recheck source type, OS version, parser syntax, permissions and whether the artefact actually exists.
Times conflict Record each source time basis and display setting before converting.
GUI result cannot be reproduced Preserve the source, version, filters, sorting and exported rows, not only a screenshot.

Clean up

Hash the final evidence package, close all working sources, remove temporary copies according to lab policy and revert the isolated VM snapshot. Do not delete the protected source, case notes or required derived evidence.