Use for authorized digital forensics including memory dumps, disk timelines, PCAP investigation, artifact triage, and IR evidence preservation.
64
76%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
View guide
Passed
No findings from the security scan
Fix and improve this skill with Tessl
tessl review fix ./skills/digital-forensics/SKILL.mdNOW: 读取 ../field-journal/precedent-pentest.md 或组织 IR 授权说明NOW: 确认是取证/溯源而非进攻性扫描NOW: 建立 case;证据只读副本优先(原始介质写保护)NEXT: tool-index;Volatility 等常手动ACT: 保全哈希 → 时间线 → 关键伪影protocol-reverse/)malware-analysis/ / threat-hunting/)□ 计算 SHA256;记录时区与采集命令
□ 工作在副本上;原始只读
□ chain of custody 备注写入 timelinevol -f mem.dmp windows.info
vol -f mem.dmp windows.pslist
vol -f mem.dmp windows.netscan
vol -f mem.dmp windows.cmdline□ 事件日志:Security / PowerShell / Sysmon
□ 持久化:Run 键、服务、计划任务、WMI
□ 执行痕迹:Amcache、Prefetch、BAM□ tshark 统计会话与 DNS
□ 导出可疑流 → protocol-reverse 或 malware C2 分析| 工具 | 用途 |
|---|---|
| Volatility 3 | 内存 |
| Timeline Explorer / Plaso | 超级时间线 |
| tshark | PCAP |
| Eric Zimmerman 工具集 | Windows 伪影 |
| Autopsy / FTK Imager | 磁盘 |
references/forensics-triage.md../malware-analysis/ ../threat-hunting/ ../protocol-reverse/上游: MASTER R25
下游: 恶意样本深挖 → malware-analysis;规则 → threat-hunting
6aa1362
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.