digital-forensics
Installation
SKILL.md
Digital Forensics & IR Artifacts
When to Use
- Investigating a suspected incident with forensic rigor.
- Building defensible timelines from disk/memory/network artifacts.
适用场景
- 内存转储分析(Volatility 2/3)
- 磁盘/ E01 / 落地文件时间线
- PCAP 溯源与协议还原(可联合
protocol-reverse/) - 主机伪影:Prefetch、Shimcache、Event Log、浏览器历史
- 应急响应 IOC 提炼(联合
malware-analysis//threat-hunting/)