Collecting Volatile Evidence From Compromised Host

Collect volatile forensic evidence from a compromised host by following the order of volatility, preserving memory, network connections, running processes, and system state with documented chain of custody before they are lost. Use before isolating, shutting down, or remediating a compromised host, especially when fileless or memory-resident malware is suspected, root cause analysis is needed, or the evidence must hold up in legal proceedings.

gabrielmoreira Updated 17 repo stars

File contents

gabrielmoreira/agent-skills-mirror/tree/main/mirrors/repos/mukul975@Anthropic-Cybersecurity-Skills/skills/collecting-volatile-evidence-from-compromised-host commit cb29e218d8

Frequently asked questions

npx skillmds@latest add gabrielmoreira/collecting-volatile-evidence-from-compromised-host