performing-endpoint-forensics-investigation

mukul975/performing-endpoint-forensics-investigation · Agent Skill (multi-file)

by mukul975 · bundle

Published · Last updated


Conducts digital forensics investigations on compromised endpoints, including memory acquisition, disk imaging, artifact analysis, and timeline reconstruction for incident response and evidence collection.

SKILL.md

Files

This skill is a package of 8 files. Install with the command above, or download the folder.

Related

  1. acquiring-disk-image-with-dd-and-dcfldd · mukul975 bundle
    Create forensically sound bit-for-bit disk images using dd and dcfldd while preserving evidence integrity through hash verification.
    24.6k
    repo stars
  2. triaging-windows-with-kape · mukul975 bundle
    Collect and parse forensic artifacts from Windows systems using KAPE for rapid DFIR triage.
    24.6k
    repo stars
  3. performing-ransomware-response · mukul975 bundle
    Executes a structured ransomware incident response from initial detection through containment, forensic analysis, decryption assessment, recovery, and post-incident hardening.
    24.6k
    repo stars
  4. extracting-memory-artifacts-with-rekall · mukul975 bundle
    Analyze Windows memory dumps for signs of compromise using the Rekall memory forensics framework, including process injection, hidden processes, and rootkit detection.
    24.6k
    repo stars
  5. hunting-for-anomalous-powershell-execution · mukul975 bundle
    Hunt for malicious PowerShell activity by analyzing Script Block Logging (Event 4104), Module Logging (Event 4103), and process creation events from Windows Event Log EVTX files to detect obfuscated commands, AMSI bypass attempts, encoded payloads, credential dumping keywords, and suspicious download cradles.
    24.6k
    repo stars
  6. analyzing-linux-system-artifacts · mukul975 bundle
    Examine Linux system artifacts including auth logs, cron jobs, shell history, and system configuration to uncover evidence of compromise or unauthorized activity.
    24.6k
    repo stars

Frequently asked questions

How do I install the performing-endpoint-forensics-investigation skill?

Run npx skillmds add mukul975/performing-endpoint-forensics-investigation in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.

What does the performing-endpoint-forensics-investigation skill do?

Conducts digital forensics investigations on compromised endpoints, including memory acquisition, disk imaging, artifact analysis, and timeline reconstruction for incident response and evidence collection. It is listed under Security, Incident Response on SkillMD.

Is performing-endpoint-forensics-investigation safe to use?

SkillMD's automated safety review verdict for this skill is CAUTION. Independent scanners report: SkillSpector: PASS, Skill Scanner: PASS. Capability flags: executes scripts. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.

Which AI agents work with performing-endpoint-forensics-investigation?

This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.

Is performing-endpoint-forensics-investigation free to use?

Yes. Installing skills from SkillMD is free. This skill is licensed under Apache-2.

Who published performing-endpoint-forensics-investigation?

mukul975 (@mukul975) published this skill. Their other Agent Skills are listed on their SkillMD profile.