Expand description
lnk-forensic — graded anomaly auditor over Windows Shell Link (.lnk) files.
Consumes a lnk_core::ShellLink and emits
forensicnomicon::report::Findings. Every anomaly is an observation
(“consistent with …”); the examiner draws the conclusions. MITRE techniques
are narrated as consistency, never as a verdict.
Enums§
- Jump
List Anomaly - A graded Jump List anomaly, layered on top of the per-link
LnkAnomalyfindings (each embedded shell link is audited withauditfor free). - LnkAnomaly
- A graded Shell Link anomaly.
Functions§
- audit
- Audit a
ShellLinkinto a typedLnkAnomalystream. - audit_
findings - Audit and convert directly to graded
Findings. - audit_
jumplist - Audit a
JumpListinto gradedFindings. - source
- The
Sourcestamp for findings this analyzer emits.