Forensics
Forensics from jmagly/ai-writing-guide.
Skills in this plugin
15- ▌ Log Analysis · jmagly-ai-writing-guideCorrelate auth.log, syslog, journald, application, and web logs to detect brute force, privilege escalation, and lateral movement.
- ▌
- ▌
- ▌ Ioc Extraction · jmagly-ai-writing-guideExtract, classify, deduplicate, and enrich IOCs from investigation artifacts; map to STIX 2.1 observables
- ▌ Cloud Forensics · jmagly-ai-writing-guideAWS, Azure, and GCP forensic investigation covering audit logs, IAM review, storage access, network flows, and compute instance forensics
- ▌ Linux Forensics · jmagly-ai-writing-guideGeneralized Linux incident response and forensic analysis covering Debian/Ubuntu, RHEL/CentOS/Rocky, and SUSE families
- ▌ Forensics Triage · jmagly-ai-writing-guideQuick triage investigation following RFC 3227 volatility order
- ▌ Memory Forensics · jmagly-ai-writing-guideVolatility 3 memory forensics workflows covering acquisition with LiME and WinPmem, and structured analysis using Volatility 3 plugin reference
- ▌ Forensics Acquire · jmagly-ai-writing-guideEvidence acquisition with chain of custody and hash verification
- ▌ Forensics Profile · jmagly-ai-writing-guideBuild target system profile via SSH or cloud API enumeration
- ▌ Forensics Quickref · jmagly-ai-writing-guideAUTO-INVOKE when user mentions forensics, incident response, IOC, log analysis, evidence preservation, breach investigation, threat hunting, attack timeline. Forensics framework quick reference — discovery phrases for incident response, log analysis, evidence preservation, IOC extraction.
- ▌
- ▌ Container Forensics · jmagly-ai-writing-guideForensic investigation of Docker, containerd/CRI-O, and Kubernetes — inventory, escape detection, eBPF runtime monitoring, RBAC and etcd audit. Use when investigating container compromise.
- ▌ Evidence Preservation · jmagly-ai-writing-guideChain of custody and evidence preservation procedures covering log collection, hash verification, custody documentation, and evidence packaging per RFC 3227
- ▌ Supply Chain Forensics · jmagly-ai-writing-guideSBOM analysis, build pipeline forensics, and dependency verification covering package integrity, build reproducibility, and CI/CD pipeline tampering