Forensics Kit

Digital forensics and incident response toolbox. Load when the operator asks about a pcap, a binary, a memory dump, a suspicious file, malware triage, IOC hunting, or post-incident analysis. Covers network (tshark), binaries (radare2, strings, binwalk, file, exiftool), memory (volatility), and pattern matching (YARA). All commands assume the artifact is local and disposable; never analyze in-place on a production system.

francescostabile e1a93d9 6.4 KB Updated

File contents

francescostabile/numasec/tree/main/packages/numasec/skills/forensics-kit commit e1a93d93b3

Frequently asked questions

npx skillmds@latest add francescostabile/forensics-kit