Forensics

Forensics from jmagly/ai-writing-guide.

Skills in this plugin

15
  1. Log Analysis · jmagly-ai-writing-guide
    Correlate auth.log, syslog, journald, application, and web logs to detect brute force, privilege escalation, and lateral movement.
    1 install
  2. Forensics Ioc · jmagly-ai-writing-guide
    Extract and enrich indicators of compromise
    1 install
  3. Forensics Hunt · jmagly-ai-writing-guide
    Threat hunt using Sigma rules against log sources
    1 install
  4. Ioc Extraction · jmagly-ai-writing-guide
    Extract, classify, deduplicate, and enrich IOCs from investigation artifacts; map to STIX 2.1 observables
    1 install
  5. Cloud Forensics · jmagly-ai-writing-guide
    AWS, Azure, and GCP forensic investigation covering audit logs, IAM review, storage access, network flows, and compute instance forensics
    1 install
  6. Linux Forensics · jmagly-ai-writing-guide
    Generalized Linux incident response and forensic analysis covering Debian/Ubuntu, RHEL/CentOS/Rocky, and SUSE families
    1 install
  7. Forensics Triage · jmagly-ai-writing-guide
    Quick triage investigation following RFC 3227 volatility order
    1 install
  8. Memory Forensics · jmagly-ai-writing-guide
    Volatility 3 memory forensics workflows covering acquisition with LiME and WinPmem, and structured analysis using Volatility 3 plugin reference
    1 install
  9. Forensics Acquire · jmagly-ai-writing-guide
    Evidence acquisition with chain of custody and hash verification
    1 install
  10. Forensics Profile · jmagly-ai-writing-guide
    Build target system profile via SSH or cloud API enumeration
    1 install
  11. Forensics Quickref · jmagly-ai-writing-guide
    AUTO-INVOKE when user mentions forensics, incident response, IOC, log analysis, evidence preservation, breach investigation, threat hunting, attack timeline. Forensics framework quick reference — discovery phrases for incident response, log analysis, evidence preservation, IOC extraction.
    1 install
  12. Forensics Timeline · jmagly-ai-writing-guide
    Build correlated event timeline from multiple sources
    1 install
  13. Container Forensics · jmagly-ai-writing-guide
    Forensic investigation of Docker, containerd/CRI-O, and Kubernetes — inventory, escape detection, eBPF runtime monitoring, RBAC and etcd audit. Use when investigating container compromise.
    1 install
  14. Evidence Preservation · jmagly-ai-writing-guide
    Chain of custody and evidence preservation procedures covering log collection, hash verification, custody documentation, and evidence packaging per RFC 3227
    0 installs
  15. Supply Chain Forensics · jmagly-ai-writing-guide
    SBOM analysis, build pipeline forensics, and dependency verification covering package integrity, build reproducibility, and CI/CD pipeline tampering
    1 install