Authorized digital forensics: memory dumps, disk timelines, PCAP investigation, artifact triage, and incident-response evidence preservation.
Scanned 9/3/2026
Install to Claude Code
npx -y skills add sickn33/agentic-awesome-skills --skill digital-forensics --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Digital Forensics?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/sickn33-digital-forensics-70c1770e)More formats (shields.io, HTML) on the badges page.
---
name: digital-forensics
description: "Authorized digital forensics: memory dumps, disk timelines, PCAP investigation, artifact triage, and incident-response evidence preservation."
risk: safe
source: "https://github.com/zhaoxuya520/reverse-skill"
source_repo: "zhaoxuya520/reverse-skill"
source_type: community
date_added: "2026-08-25"
license: "MIT"
license_source: "https://github.com/zhaoxuya520/reverse-skill/blob/main/LICENSE"
---
# Digital Forensics & IR Artifacts
## When to Use
- Investigating a suspected incident with forensic rigor.
- Building defensible timelines from disk/memory/network artifacts.
## 适用场景
- 内存转储分析(Volatility 2/3)
- 磁盘/ E01 / 落地文件时间线
- PCAP 溯源与协议还原(可联合 `protocol-reverse/`)
- 主机伪影:Prefetch、Shimcache、Event Log、浏览器历史
- 应急响应 IOC 提炼(联合 `malware-analysis/` / `threat-hunting/`)
## 工作流
### 1. 保全
```text
□ 计算 SHA256;记录时区与采集命令
□ 工作在副本上;原始只读
□ chain of custody 备注写入 timeline
```
### 2. 内存
```bash
vol -f mem.dmp windows.info
vol -f mem.dmp windows.pslist
vol -f mem.dmp windows.netscan
vol -f mem.dmp windows.cmdline
```
### 3. 主机伪影
```text
□ 事件日志:Security / PowerShell / Sysmon
□ 持久化:Run 键、服务、计划任务、WMI
□ 执行痕迹:Amcache、Prefetch、BAM
```
### 4. 网络
```text
□ tshark 统计会话与 DNS
□ 导出可疑流 → protocol-reverse 或 malware C2 分析
```
## 工具链
| 工具 | 用途 |
|------|------|
| Volatility 3 | 内存 |
| Timeline Explorer / Plaso | 超级时间线 |
| tshark | PCAP |
| Eric Zimmerman 工具集 | Windows 伪影 |
| Autopsy / FTK Imager | 磁盘 |
## 参考
- `references/forensics-triage.md`
- `../malware-analysis/` `../threat-hunting/` `../protocol-reverse/`
## 路由上下文
**上游**: MASTER R25
**下游**: 恶意样本深挖 → malware-analysis;规则 → threat-hunting
## 任务完成自检
- [ ] 是否保全哈希与副本策略?
- [ ] 时间线是否可复核?
- [ ] IOC 是否脱敏分级?
- [ ] Checklist?
## Limitations
- Chain-of-custody requirements apply; work on verified copies, never originals.
- Encrypted or anti-forensic artifacts may be unrecoverable.
> Adapted from [zhaoxuya520/reverse-skill](https://github.com/zhaoxuya520/reverse-skill) (MIT).
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!