Dfir skills
Free agent skills tagged dfir, ready to install into any SKILL.md-compatible agent.
9 skills
Building Incident Timeline with Timesketch
mukul975
Collaboratively analyze forensic timelines for incident investigations.
Generating Forensic Timelines
mukul975
Transform Windows event logs into actionable forensic timelines.
Hunting EVTX with Chainsaw
mukul975
Rapidly analyze Windows event logs for threats.
Implementing Velociraptor for IR Collection
mukul975
Streamline endpoint forensic artifact collection for incident response.
Eradicating Malware from Infected Systems
mukul975
Systematically remove malware and restore clean states.
Fleet Hunting with Velociraptor
mukul975
Conduct fleet-wide threat hunts with deep endpoint visibility.
Collecting Volatile Evidence
mukul975
Capture critical data from compromised hosts before it's lost.
Analyzing Windows Amcache Artifacts
mukul975
Extract and analyze program execution data from Windows Amcache.
Memory Forensics with Volatility
mukul975
Analyze RAM dumps for malware and process injection evidence.
