[DOCUMENTATION ONLY] [仅文档] Offline malware triage, capability analysis, memory forensics, timeline, IOC packaging, and incident-response workflow.
Pro scans all 2 files and shows the line behind each finding
Scanned 9/24/2026
npx -y skills add alicewe1/alice_skill --skill eni-malware-ir-workflow --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Eni Malware Ir Workflow?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/alicewe1-eni-malware-ir-workflow)More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.
---
name: eni-malware-ir-workflow
description: "[DOCUMENTATION ONLY] [仅文档] Offline malware triage, capability analysis, memory forensics, timeline, IOC packaging, and incident-response workflow."
x-alice-class: reverse
---
> 仅文档:本 Skill 提供方法与检查表,不宣称自带可执行脚本。
# Malware IR Workflow
Hash and preserve samples. Use capability-first triage, static reverse analysis, and Volatility-style memory context. Separate observed facts from hypotheses. Build a timeline, IOC package, confidence labels, and verification notes.
Persist checkpoints before long runs. Record commands, versions, hashes, evidence paths, assumptions, and verification results. Chain through eni-universal-workflow and finish with delivery.
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!