defense-dfir-triage
Installation
SKILL.md
DFIR triage & investigation
When it applies
A host or account is suspected compromised and you need to determine what happened, scope it, and preserve evidence — quickly, without destroying volatile data.
Why it works
Attacker activity leaves artifacts across a known set of locations (execution, persistence, logons, network). A disciplined order — preserve volatile first, then map to ATT&CK — gives a timeline and scope instead of a guess.