forensics-assist

Installation
SKILL.md

Forensics Assist

Audit-grade vs. forensics-grade: this skill supports incident-response-grade investigation with evidence that can later be supplemented for legal proceedings, but it is not on its own a fully chain-of-custody-certified forensics output. Specialized forensic teams (an internal forensics cell or an external partner such as Fox-IT or Northwave) handle the courtroom-grade work where required. The skill structures hash validation, write-blocker discipline, and timeline reconstruction so the output is usable for IR plus any follow-up forensics.

When to use

An incident often calls for forensic investigation in parallel with IR action. This skill provides the practical lens for the blue-team side: what you capture, how you analyse it, and what you hand off to IR or specialized forensics.

Triggers on:

  • A question like "memory analysis on this dump", "disk-image hygiene check", "build a timeline from this event log + filesystem", "what is known from MFT", "Volatility plugin choice".
  • A handoff from ir-runbook (forensics step inside the response), malware-triage (memory-extracted binary), log-triage (host investigation after an anomaly).
  • A suspect host snapshot where you must determine "what happened, how far did it go, how long has it been there".
  • Periodic training or post-incident review where a sample investigation is repeated.

When NOT (handoff)

Installs
3
GitHub Stars
4
First Seen
May 18, 2026
forensics-assist — roodlicht/accans-sec-skills