disk-forensics
Installation
SKILL.md
Disk Forensics — Digital Evidence Analysis
Analyze disk images and file systems to recover evidence, reconstruct timelines, and identify artifacts.
Evidence Handling Principles
- Always work on copies, never originals
- Verify image integrity with hash comparison before analysis
- Mount everything read-only
- Document every command and finding
- Preserve timestamps — never modify source evidence
Methodology
Step 1: Image Identification and Integrity
Identify the image format and verify integrity: