digital-forensics
Use for authorized digital forensics including memory dumps, disk timelines, PCAP investigation, artifact triage, and IR evidence preservation.
By zhaoxuya520 · 659 installs
npx skills add zhaoxuya520/reverse-skill --skill digital-forensics
Source repository · Upstream listing
Digital Forensics & IR Artifacts
ACTION REQUIRED(读完后立刻执行)
1. NOW : 读取 ../field journal/precedent pentest.md 或组织 IR 授权说明
2. NOW : 确认是 取证/溯源 而非进攻性扫描
3. NOW : 建立 case;证据只读副本优先(原始介质写保护)
4. NEXT : tool index;Volatility 等常手动
5. ACT : 保全哈希 → 时间线 → 关键伪影
适用场景
内存转储分析(Volatility 2/3)
磁盘/ E01 / 落地文件时间线
PCAP 溯源与协议还原(可联合 protocol reverse/ )
主机伪影:Prefetch、Shimcache、Event Log、浏览器历史
应急响应 IOC 提炼(联合 malware analysis/ / threat hunting/ )
工作流
1. 保全
2. 内存
3. 主机伪影
4. 网络
工具链
工具 用途
Volatility 3 内存
Timeline Explorer / Plaso 超级时间线
tshark PCAP
Eric Zimmerman 工具集 Windows 伪影
Autopsy / FTK Imager 磁盘
参考
references/forensics triage.md
../malware analysis/ ../threat hunting/ ../protocol reverse/
路由上下文
上游 : MASTER R25
下游 : 恶意样本深挖 → malware analysis;规则 → threat hunting
任务完成自检
[ ] 是否保全哈希与副本策略?
[ ] 时间线是否可复核?
[ ] IOC 是否脱敏分级?
[ ] Checklist?