Cyber Blue Forensics
Cyber Blue Forensics from theheavenlyd3mon/hermes-profiles.
Skills in this plugin
33- ▌ Containing Active Breach · theheavenlyd3mon bundleExecutes containment strategies to stop active adversary operations and prevent lateral movement during a confirmed security breach. Implements short-term and long-term containment using network segmentation, endpoint isolation, credential revocation, and access control modifications. Activates for requests involving breach containment, lateral movement prevention, network isolation, active threat containment, or live incident response.
- ▌ Triaging Security Incident · theheavenlyd3mon bundlePerforms initial triage of security incidents to determine severity, scope, and required response actions using the NIST SP 800-61r3 and SANS PICERL frameworks. Classifies incidents by type, assigns priority based on business impact, and routes to appropriate response teams. Activates for requests involving incident triage, security alert classification, severity assessment, incident prioritization, or initial incident analysis.
- ▌ Analyzing PDF Malware With Pdfid · theheavenlyd3mon bundleAnalyzes malicious PDF files using PDFiD, pdf-parser, and peepdf to identify embedded JavaScript, shellcode, exploits, and suspicious objects without opening the document. Determines the attack vector and extracts embedded payloads for further analysis. Activates for requests involving PDF malware analysis, malicious document analysis, PDF exploit investigation, or suspicious attachment triage.
- ▌ Recovering From Ransomware Attack · theheavenlyd3mon bundleExecutes structured recovery from a ransomware incident following NIST and CISA frameworks, including environment isolation, forensic evidence preservation, clean infrastructure rebuild, prioritized system restoration from verified backups, credential reset, and validation against re-infection. Covers Active Directory recovery, database restoration, and application stack rebuild in dependency order. Activates for requests involving ransomware recovery, post-encryption restoration, or disaster recovery from ransomware.
- ▌ Building Incident Response Playbook · theheavenlyd3mon bundleDesigns and documents structured incident response playbooks that define step-by-step procedures for specific incident types aligned with NIST SP 800-61r3 and SANS PICERL frameworks. Covers playbook structure, decision trees, escalation criteria, RACI matrices, and integration with SOAR platforms. Activates for requests involving IR playbook creation, incident response procedure documentation, response runbook development, or SOAR playbook design.
- ▌ Collecting Indicators Of Compromise · theheavenlyd3mon bundleSystematically collects, categorizes, and distributes indicators of compromise (IOCs) during and after security incidents to enable detection, blocking, and threat intelligence sharing. Covers network, host, email, and behavioral indicators using STIX/TAXII formats and threat intelligence platforms. Activates for requests involving IOC collection, indicator extraction, threat indicator sharing, compromise indicators, STIX export, or IOC enrichment.
- ▌ Collecting Open Source Intelligence · theheavenlyd3mon bundleCollects and synthesizes open-source intelligence (OSINT) about threat actors, malicious infrastructure, and attack campaigns using publicly available data sources, passive reconnaissance tools, and dark web monitoring. Use when investigating external threat actor infrastructure, performing pre-engagement reconnaissance for authorized red team assessments, or enriching CTI reports with publicly available adversary context. Activates for requests involving Maltego, Shodan, OSINT framework, SpiderFoot, or infrastructure reconnaissance.
- ▌ Analyzing Malicious Url With Urlscan · theheavenlyd3mon bundleURLScan.io is a free service for scanning and analyzing suspicious URLs. It captures screenshots, DOM content, HTTP transactions, JavaScript behavior, and network connections of web pages in an isolat
- ▌ Building Incident Response Dashboard · theheavenlyd3mon bundleBuilds real-time incident response dashboards in Splunk, Elastic, or Grafana to provide SOC analysts and leadership with situational awareness during active incidents, tracking affected systems, containment status, IOC spread, and response timeline. Use when IR teams need unified visibility during incident coordination and post-incident reporting.
- ▌ Performing Sqlite Database Forensics · theheavenlyd3mon bundlePerform forensic analysis of SQLite databases to recover deleted records from freelists and WAL files, decode encoded timestamps, and extract evidence from browser history, messaging apps, and mobile device databases.
- ▌ Investigating Phishing Email Incident · theheavenlyd3mon bundleInvestigates phishing email incidents from initial user report through header analysis, URL/attachment detonation, impacted user identification, and containment actions using SOC tools like Splunk, Microsoft Defender, and sandbox analysis platforms. Use when a reported phishing email requires full incident investigation to determine scope and impact.
- ▌ Acquiring Disk Image With Dd And Dcfldd · theheavenlyd3mon bundleCreate forensically sound bit-for-bit disk images using dd and dcfldd while preserving evidence integrity through hash verification.
- ▌ Investigating Insider Threat Indicators · theheavenlyd3mon bundleInvestigates insider threat indicators including data exfiltration attempts, unauthorized access patterns, policy violations, and pre-departure behaviors using SIEM analytics, DLP alerts, and HR data correlation. Use when SOC teams receive insider threat referrals from HR, detect anomalous data movement by employees, or need to build investigation timelines for potential insider threats.
- ▌ Performing Disk Forensics Investigation · theheavenlyd3mon bundleConducts disk forensics investigations using forensic imaging, file system analysis, artifact recovery, and timeline reconstruction to support incident response cases. Utilizes tools such as FTK Imager, Autopsy, and The Sleuth Kit for evidence acquisition, deleted file recovery, and artifact examination. Activates for requests involving disk forensics, hard drive analysis, forensic imaging, file recovery, evidence acquisition, or digital forensic investigation.
- ▌ Analyzing Network Traffic With Wireshark · theheavenlyd3mon bundleCaptures and analyzes network packet data using Wireshark and tshark to identify malicious traffic patterns, diagnose protocol issues, extract artifacts, and support incident response investigations on authorized network segments.
- ▌ Collecting Threat Intelligence With Misp · theheavenlyd3mon bundleMISP (Malware Information Sharing Platform) is an open-source threat intelligence platform for gathering, sharing, storing, and correlating Indicators of Compromise (IOCs) of targeted attacks, threat
- ▌ Analyzing Azure Activity Logs For Threats · theheavenlyd3mon bundleQueries Azure Monitor activity logs and sign-in logs via azure-monitor-query to detect suspicious administrative operations, impossible travel, privilege escalation, and resource modifications. Builds KQL queries for threat hunting in Azure environments. Use when investigating suspicious Azure tenant activity or building cloud SIEM detections.
- ▌ Eradicating Malware From Infected Systems · theheavenlyd3mon bundleSystematically remove malware, backdoors, and attacker persistence mechanisms from infected systems while ensuring complete eradication and preventing re-infection.
- ▌ Investigating Ransomware Attack Artifacts · theheavenlyd3mon bundleIdentify, collect, and analyze ransomware attack artifacts to determine the variant, initial access vector, encryption scope, and recovery options.
- ▌ Analyzing Packed Malware With Upx Unpacker · theheavenlyd3mon bundleIdentifies and unpacks UPX-packed and other packed malware samples to expose the original executable code for static analysis. Covers both standard UPX unpacking and handling modified UPX headers that prevent automated decompression. Activates for requests involving malware unpacking, UPX decompression, packer removal, or preparing packed samples for analysis.
- ▌ Building Incident Timeline With Timesketch · theheavenlyd3mon bundleBuild collaborative forensic incident timelines using Timesketch to ingest, normalize, and analyze multi-source event data for attack chain reconstruction and investigation documentation.
- ▌ Performing Network Packet Capture Analysis · theheavenlyd3mon bundlePerform forensic analysis of network packet captures (PCAP/PCAPNG) using Wireshark, tshark, and tcpdump to reconstruct network communications, extract transferred files, identify malicious traffic, and establish evidence of data exfiltration or command-and-control activity.
- ▌ Performing Network Forensics With Wireshark · theheavenlyd3mon bundleCapture and analyze network traffic using Wireshark and tshark to reconstruct network events, extract artifacts, and identify malicious communications.
- ▌ Triaging Security Incident With Ir Playbook · theheavenlyd3mon bundleClassify and prioritize security incidents using structured IR playbooks to determine severity, assign response teams, and initiate appropriate response procedures.
- ▌ Performing Memory Forensics With Volatility3 · theheavenlyd3mon bundleAnalyze volatile memory dumps using Volatility 3 to extract running processes, network connections, loaded modules, and evidence of malicious activity.
- ▌ Analyzing Office365 Audit Logs For Compromise · theheavenlyd3mon bundleParse Office 365 Unified Audit Logs via Microsoft Graph API to detect email forwarding rule creation, inbox delegation, suspicious OAuth app grants, and other indicators of account compromise.
- ▌ Performing Network Traffic Analysis With Zeek · theheavenlyd3mon bundleDeploy Zeek network security monitor to capture, parse, and analyze network traffic metadata for threat detection, anomaly identification, and forensic investigation.
- ▌ Performing Network Traffic Analysis With Tshark · theheavenlyd3mon bundleAutomate network traffic analysis using tshark and pyshark for protocol statistics, suspicious flow detection, DNS anomaly identification, and IOC extraction from PCAP files
- ▌ Collecting Volatile Evidence From Compromised Host · theheavenlyd3mon bundleCollect volatile forensic evidence from a compromised system following order of volatility, preserving memory, network connections, processes, and system state before they are lost.
- ▌ Performing Log Analysis For Forensic Investigation · theheavenlyd3mon bundleCollect, parse, and correlate system, application, and security logs to reconstruct events and establish timelines during forensic investigations.
- ▌ Analyzing Memory Forensics With Lime And Volatility · theheavenlyd3mon bundlePerforms Linux memory acquisition using LiME (Linux Memory Extractor) kernel module and analysis with Volatility 3 framework. Extracts process lists, network connections, bash history, loaded kernel modules, and injected code from Linux memory images. Use when performing incident response on compromised Linux systems.
- ▌ Performing Memory Forensics With Volatility3 Plugins · theheavenlyd3mon bundleAnalyze memory dumps using Volatility3 plugins to detect injected code, rootkits, credential theft, and malware artifacts in Windows, Linux, and macOS memory images.
- ▌ Performing Windows Artifact Analysis With Eric Zimmerman Too · theheavenlyd3mon bundlePerform comprehensive Windows forensic artifact analysis using Eric Zimmerman's open-source EZ Tools suite including KAPE, MFTECmd, PECmd, LECmd, JLECmd, and Timeline Explorer for parsing registry hives, prefetch files, event logs, and file system metadata.