digital-forensics

Use for authorized digital forensics including memory dumps, disk timelines, PCAP investigation, artifact triage, and IR evidence preservation.

By zhaoxuya520 · 659 installs

npx skills add zhaoxuya520/reverse-skill --skill digital-forensics

Source repository · Upstream listing

Digital Forensics & IR Artifacts ACTION REQUIRED(读完后立刻执行) 1. NOW : 读取 ../field journal/precedent pentest.md 或组织 IR 授权说明 2. NOW : 确认是 取证/溯源 而非进攻性扫描 3. NOW : 建立 case;证据只读副本优先(原始介质写保护) 4. NEXT : tool index;Volatility 等常手动 5. ACT : 保全哈希 → 时间线 → 关键伪影 适用场景 内存转储分析(Volatility 2/3) 磁盘/ E01 / 落地文件时间线 PCAP 溯源与协议还原(可联合 protocol reverse/ ) 主机伪影:Prefetch、Shimcache、Event Log、浏览器历史 应急响应 IOC 提炼(联合 malware analysis/ / threat hunting/ ) 工作流 1. 保全 2. 内存 3. 主机伪影 4. 网络 工具链 工具 用途 Volatility 3 内存 Timeline Explorer / Plaso 超级时间线 tshark PCAP Eric Zimmerman 工具集 Windows 伪影 Autopsy / FTK Imager 磁盘 参考 references/forensics triage.md ../malware analysis/ ../threat hunting/ ../protocol reverse/ 路由上下文 上游 : MASTER R25 下游 : 恶意样本深挖 → malware analysis;规则 → threat hunting 任务完成自检 [ ] 是否保全哈希与副本策略? [ ] 时间线是否可复核? [ ] IOC 是否脱敏分级? [ ] Checklist?