Log Forensics

Investigate an incident from logs: pick the Windows Security/System/PowerShell/Sysmon event IDs, Linux auth/audit/systemd/cron/shell-history artifacts, and web server or proxy logs that answer the question, normalize time zones, merge everything into one UTC super-timeline, pivot user to host to process to network, and preserve evidence properly. Use it whenever someone pastes or points at exported logs (CSV, JSON, EVTX exports, auth.log, access.log), asks "what happened on this host", "when did they get in", "what did this account do", "build a timeline", "which event IDs should I pull", or needs a forensic narrative for an incident report, even if they never say forensics.

ftrout Updated

File contents

ftrout/secops-claude-skills/tree/main/skills/log-forensics commit 74f660b1fe

Frequently asked questions

npx skillmds@latest add ftrout/log-forensics