Cyber Blue Forensics

Cyber Blue Forensics from theheavenlyd3mon/hermes-profiles.

by @theheavenlyd3mon 33 skills

Skills in this plugin

33
  1. Containing Active Breach · theheavenlyd3mon bundle
    Executes containment strategies to stop active adversary operations and prevent lateral movement during a confirmed security breach. Implements short-term and long-term containment using network segmentation, endpoint isolation, credential revocation, and access control modifications. Activates for requests involving breach containment, lateral movement prevention, network isolation, active threat containment, or live incident response.
    28 repo stars
  2. Triaging Security Incident · theheavenlyd3mon bundle
    Performs initial triage of security incidents to determine severity, scope, and required response actions using the NIST SP 800-61r3 and SANS PICERL frameworks. Classifies incidents by type, assigns priority based on business impact, and routes to appropriate response teams. Activates for requests involving incident triage, security alert classification, severity assessment, incident prioritization, or initial incident analysis.
    28 repo stars
  3. Analyzing PDF Malware With Pdfid · theheavenlyd3mon bundle
    Analyzes malicious PDF files using PDFiD, pdf-parser, and peepdf to identify embedded JavaScript, shellcode, exploits, and suspicious objects without opening the document. Determines the attack vector and extracts embedded payloads for further analysis. Activates for requests involving PDF malware analysis, malicious document analysis, PDF exploit investigation, or suspicious attachment triage.
    28 repo stars
  4. Recovering From Ransomware Attack · theheavenlyd3mon bundle
    Executes structured recovery from a ransomware incident following NIST and CISA frameworks, including environment isolation, forensic evidence preservation, clean infrastructure rebuild, prioritized system restoration from verified backups, credential reset, and validation against re-infection. Covers Active Directory recovery, database restoration, and application stack rebuild in dependency order. Activates for requests involving ransomware recovery, post-encryption restoration, or disaster recovery from ransomware.
    28 repo stars
  5. Building Incident Response Playbook · theheavenlyd3mon bundle
    Designs and documents structured incident response playbooks that define step-by-step procedures for specific incident types aligned with NIST SP 800-61r3 and SANS PICERL frameworks. Covers playbook structure, decision trees, escalation criteria, RACI matrices, and integration with SOAR platforms. Activates for requests involving IR playbook creation, incident response procedure documentation, response runbook development, or SOAR playbook design.
    28 repo stars
  6. Collecting Indicators Of Compromise · theheavenlyd3mon bundle
    Systematically collects, categorizes, and distributes indicators of compromise (IOCs) during and after security incidents to enable detection, blocking, and threat intelligence sharing. Covers network, host, email, and behavioral indicators using STIX/TAXII formats and threat intelligence platforms. Activates for requests involving IOC collection, indicator extraction, threat indicator sharing, compromise indicators, STIX export, or IOC enrichment.
    28 repo stars
  7. Collecting Open Source Intelligence · theheavenlyd3mon bundle
    Collects and synthesizes open-source intelligence (OSINT) about threat actors, malicious infrastructure, and attack campaigns using publicly available data sources, passive reconnaissance tools, and dark web monitoring. Use when investigating external threat actor infrastructure, performing pre-engagement reconnaissance for authorized red team assessments, or enriching CTI reports with publicly available adversary context. Activates for requests involving Maltego, Shodan, OSINT framework, SpiderFoot, or infrastructure reconnaissance.
    28 repo stars
  8. Analyzing Malicious Url With Urlscan · theheavenlyd3mon bundle
    URLScan.io is a free service for scanning and analyzing suspicious URLs. It captures screenshots, DOM content, HTTP transactions, JavaScript behavior, and network connections of web pages in an isolat
    28 repo stars
  9. Building Incident Response Dashboard · theheavenlyd3mon bundle
    Builds real-time incident response dashboards in Splunk, Elastic, or Grafana to provide SOC analysts and leadership with situational awareness during active incidents, tracking affected systems, containment status, IOC spread, and response timeline. Use when IR teams need unified visibility during incident coordination and post-incident reporting.
    28 repo stars
  10. Performing Sqlite Database Forensics · theheavenlyd3mon bundle
    Perform forensic analysis of SQLite databases to recover deleted records from freelists and WAL files, decode encoded timestamps, and extract evidence from browser history, messaging apps, and mobile device databases.
    28 repo stars
  11. Investigating Phishing Email Incident · theheavenlyd3mon bundle
    Investigates phishing email incidents from initial user report through header analysis, URL/attachment detonation, impacted user identification, and containment actions using SOC tools like Splunk, Microsoft Defender, and sandbox analysis platforms. Use when a reported phishing email requires full incident investigation to determine scope and impact.
    28 repo stars
  12. Acquiring Disk Image With Dd And Dcfldd · theheavenlyd3mon bundle
    Create forensically sound bit-for-bit disk images using dd and dcfldd while preserving evidence integrity through hash verification.
    28 repo stars
  13. Investigating Insider Threat Indicators · theheavenlyd3mon bundle
    Investigates insider threat indicators including data exfiltration attempts, unauthorized access patterns, policy violations, and pre-departure behaviors using SIEM analytics, DLP alerts, and HR data correlation. Use when SOC teams receive insider threat referrals from HR, detect anomalous data movement by employees, or need to build investigation timelines for potential insider threats.
    28 repo stars
  14. Performing Disk Forensics Investigation · theheavenlyd3mon bundle
    Conducts disk forensics investigations using forensic imaging, file system analysis, artifact recovery, and timeline reconstruction to support incident response cases. Utilizes tools such as FTK Imager, Autopsy, and The Sleuth Kit for evidence acquisition, deleted file recovery, and artifact examination. Activates for requests involving disk forensics, hard drive analysis, forensic imaging, file recovery, evidence acquisition, or digital forensic investigation.
    28 repo stars
  15. Analyzing Network Traffic With Wireshark · theheavenlyd3mon bundle
    Captures and analyzes network packet data using Wireshark and tshark to identify malicious traffic patterns, diagnose protocol issues, extract artifacts, and support incident response investigations on authorized network segments.
    28 repo stars
  16. Collecting Threat Intelligence With Misp · theheavenlyd3mon bundle
    MISP (Malware Information Sharing Platform) is an open-source threat intelligence platform for gathering, sharing, storing, and correlating Indicators of Compromise (IOCs) of targeted attacks, threat
    28 repo stars
  17. Analyzing Azure Activity Logs For Threats · theheavenlyd3mon bundle
    Queries Azure Monitor activity logs and sign-in logs via azure-monitor-query to detect suspicious administrative operations, impossible travel, privilege escalation, and resource modifications. Builds KQL queries for threat hunting in Azure environments. Use when investigating suspicious Azure tenant activity or building cloud SIEM detections.
    28 repo stars
  18. Eradicating Malware From Infected Systems · theheavenlyd3mon bundle
    Systematically remove malware, backdoors, and attacker persistence mechanisms from infected systems while ensuring complete eradication and preventing re-infection.
    28 repo stars
  19. Investigating Ransomware Attack Artifacts · theheavenlyd3mon bundle
    Identify, collect, and analyze ransomware attack artifacts to determine the variant, initial access vector, encryption scope, and recovery options.
    28 repo stars
  20. Analyzing Packed Malware With Upx Unpacker · theheavenlyd3mon bundle
    Identifies and unpacks UPX-packed and other packed malware samples to expose the original executable code for static analysis. Covers both standard UPX unpacking and handling modified UPX headers that prevent automated decompression. Activates for requests involving malware unpacking, UPX decompression, packer removal, or preparing packed samples for analysis.
    28 repo stars
  21. Building Incident Timeline With Timesketch · theheavenlyd3mon bundle
    Build collaborative forensic incident timelines using Timesketch to ingest, normalize, and analyze multi-source event data for attack chain reconstruction and investigation documentation.
    28 repo stars
  22. Performing Network Packet Capture Analysis · theheavenlyd3mon bundle
    Perform forensic analysis of network packet captures (PCAP/PCAPNG) using Wireshark, tshark, and tcpdump to reconstruct network communications, extract transferred files, identify malicious traffic, and establish evidence of data exfiltration or command-and-control activity.
    28 repo stars
  23. Performing Network Forensics With Wireshark · theheavenlyd3mon bundle
    Capture and analyze network traffic using Wireshark and tshark to reconstruct network events, extract artifacts, and identify malicious communications.
    28 repo stars
  24. Triaging Security Incident With Ir Playbook · theheavenlyd3mon bundle
    Classify and prioritize security incidents using structured IR playbooks to determine severity, assign response teams, and initiate appropriate response procedures.
    28 repo stars
  25. Performing Memory Forensics With Volatility3 · theheavenlyd3mon bundle
    Analyze volatile memory dumps using Volatility 3 to extract running processes, network connections, loaded modules, and evidence of malicious activity.
    28 repo stars
  26. Analyzing Office365 Audit Logs For Compromise · theheavenlyd3mon bundle
    Parse Office 365 Unified Audit Logs via Microsoft Graph API to detect email forwarding rule creation, inbox delegation, suspicious OAuth app grants, and other indicators of account compromise.
    28 repo stars
  27. Performing Network Traffic Analysis With Zeek · theheavenlyd3mon bundle
    Deploy Zeek network security monitor to capture, parse, and analyze network traffic metadata for threat detection, anomaly identification, and forensic investigation.
    28 repo stars
  28. Performing Network Traffic Analysis With Tshark · theheavenlyd3mon bundle
    Automate network traffic analysis using tshark and pyshark for protocol statistics, suspicious flow detection, DNS anomaly identification, and IOC extraction from PCAP files
    28 repo stars
  29. Collecting Volatile Evidence From Compromised Host · theheavenlyd3mon bundle
    Collect volatile forensic evidence from a compromised system following order of volatility, preserving memory, network connections, processes, and system state before they are lost.
    28 repo stars
  30. Performing Log Analysis For Forensic Investigation · theheavenlyd3mon bundle
    Collect, parse, and correlate system, application, and security logs to reconstruct events and establish timelines during forensic investigations.
    28 repo stars
  31. Analyzing Memory Forensics With Lime And Volatility · theheavenlyd3mon bundle
    Performs Linux memory acquisition using LiME (Linux Memory Extractor) kernel module and analysis with Volatility 3 framework. Extracts process lists, network connections, bash history, loaded kernel modules, and injected code from Linux memory images. Use when performing incident response on compromised Linux systems.
    28 repo stars
  32. Performing Memory Forensics With Volatility3 Plugins · theheavenlyd3mon bundle
    Analyze memory dumps using Volatility3 plugins to detect injected code, rootkits, credential theft, and malware artifacts in Windows, Linux, and macOS memory images.
    28 repo stars
  33. Performing Windows Artifact Analysis With Eric Zimmerman Too · theheavenlyd3mon bundle
    Perform comprehensive Windows forensic artifact analysis using Eric Zimmerman's open-source EZ Tools suite including KAPE, MFTECmd, PECmd, LECmd, JLECmd, and Timeline Explorer for parsing registry hives, prefetch files, event logs, and file system metadata.
    28 repo stars