Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
GhostTrace — Read-only Windows forensic scanner for software traces — persistence, execution artifacts (Prefetch, Shimcache, BAM), user activity and Ghost Tasks correlation. 20+ modules mapped to MITRE ATT&CK. | Kitploit
Tools/GitHubGitHub/devzinh/ghosttrace
Memory ForensicsPersistence MechanismsForensicsDigital ForensicsThreat IntelligenceIncident Response
GitHubdevzinh/ghosttrace

GhostTrace

Read-only Windows forensic scanner for software traces — persistence, execution artifacts (Prefetch, Shimcache, BAM), user activity and Ghost Tasks correlation. 20+ modules mapped to MITRE ATT&CK.

View Repository
202 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
Website

GhostTrace

Find what software left behind on Windows, before it finds its way back.

GhostTrace is a local Windows forensic trace hunter for incident responders, system administrators, and security-minded power users. It maps persistence, execution, activity, and leftover artifacts into a reviewable record, then offers tightly constrained cleanup only when you explicitly choose it.

CI Release Windows .NET License

Download | Requirements | Quick start | Capabilities | Safety model | Roadmap | Portuguese (Brazil)


Why GhostTrace

Uninstalling an application does not always remove its operational footprint. Startup entries, scheduled tasks, cached execution evidence, registry values, services, and folders can remain long after the installer reports success.

GhostTrace turns that broad question into a focused, local investigation:

  • One focused hunt across NN forensic modules.
  • Evidence by source, with findings, errors, and metadata kept per module.
  • Offline by design, with no telemetry, uploads, or cloud dependency.
  • Audit-ready output, including TXT records, JSON outputs for directed collectors, and cleanup logs.
  • Human-controlled cleanup, never automatic remediation.

Requirements

ItemRequirement
Operating systemWindows 10 or 11, x64
PrivilegesAdministrator, required to read protected artifacts
RuntimeNone. The MSI is self-contained.
Disk ~NN MB installed, plus space for report output

Verify your download

GhostTrace reads protected Windows artifacts and runs elevated. Verify the installer before executing it, especially on a host you are investigating.

Get-FileHash .\GhostTrace-1.5.0-x64.msi -Algorithm SHA256

Compare the result against SHA256SUMS.txt published with each release.

The installer is not code-signed yet, so SmartScreen and some EDR products will flag it on first run. Verify the hash rather than dismissing the warning.

Quick start

Install

Download the latest x64 MSI from Releases:

GhostTrace-<version>-x64.msi

The package is self-contained, so the target machine does not need a pre-installed .NET runtime. Run GhostTrace as Administrator to access protected Windows artifacts.

Hunt a software name

GhostTrace.CLI scan --name nvidia

The interactive flow shows progress, groups findings by technique, and can export a record of the investigation. If safe cleanup candidates exist, you must select them and type a confirmation phrase before any removal occurs.

A trimmed example of what that produces:

$ GhostTrace.CLI scan --name nvidia

  MODULE                        FINDINGS  STATUS
  PersistenceScanModule                2  OK
  ScheduledTasksScanModule             1  OK
  TaskCacheScanModule                  1  PartialSuccess
  PrefetchScanModule                   4  OK

  [Persistence] HKLM\...\Run\NvBackend
      -> C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe (missing)

  [Ghost Task] TaskCache\Tree entry with no COM counterpart (T1053.005)
      \NvProfileUpdaterOnLogon_{...}

  TaskCacheScanModule: PartialSuccess. 2 keys unreadable (access denied).

GhostTrace running in the terminal

Run it in automation

GhostTrace.CLI scan --name nvidia --quiet --output C:\Cases\Host1

--quiet creates a non-interactive TXT record. A report write failure returns a non-zero exit code, so automation does not silently succeed without an artifact.

Essential commands

GoalCommand
Open the interactive menuGhostTrace.CLI
Run a full triageGhostTrace.CLI scan
Hunt a named applicationGhostTrace.CLI scan --name <n>
Write a script-friendly scan recordGhostTrace.CLI scan --name <n> --quiet --output <directory>
Correlate Task Scheduler COM and TaskCacheGhostTrace.CLI scan-tasks-correlate-json --output <report.json>
Inspect a directory, Registry key, or Event Logscan-fs-json, scan-reg-json, scan-evt-json

Choose the interface language with --lang:

GhostTrace.CLI scan --name nvidia --lang en
GhostTrace.CLI --lang pt-BR

Exit codes

CodeMeaning
0Scan completed and any requested report was written
1Invalid arguments or unsupported environment
2Report write failure
3Cancelled by the operator

From collection to review

GhostTrace investigation workflow

  1. GhostTrace runs the modules available for the selected collection.
  2. Each module returns its own findings, errors, and metadata.
  3. The CLI renders a concise summary and writes a local record when requested.
  4. Any selected cleanup operation is written to a separate audit log.

What it collects

AreaEvidence sources
PersistenceRun/RunOnce, Startup, services, Winlogon, IFEO, AppInit, LSA, Active Setup, WMI, and scheduled tasks
ExecutionPrefetch, Shimcache, BAM/DAM, UserAssist, and MUICache
User activityPowerShell history, outbound RDP history, RecentDocs, USB, and network artifacts
Installed software and leftoversUninstall entries, StartupApproved, Program Files, ProgramData, and AppData traces
Scheduled task correlationCOM and TaskCache discrepancies used to investigate Ghost Tasks (T1053.005)

GhostTrace module coverage

Module reference (internal collector names)

Persistence

ModuleSource
PersistenceScanModuleRun/RunOnce and Startup folders
ServicesScanModuleService and driver ImagePath values
AsepScanModuleWinlogon, IFEO, AppInit, LSA, and Active Setup
ScheduledTasksScanModuleTask Scheduler COM, including hidden tasks
TaskCacheScanModuleTaskCache\Tree anomalies
WmiPersistenceScanModule__EventFilter, __EventConsumer, and bindings

Execution and activity

ModuleSource
PrefetchScanModuleWindows 10/11 .pf files, including XPRESS-Huffman compression
ShimcacheScanModuleAppCompatCache
BamScanModuleBAM/DAM records by SID
UserAssistScanModuleGUI launches and usage counts
Download Tool