forensics▌
38 indexed skills · max 10 per page
analyzing-slack-space-and-file-system-artifacts
mukul975/Anthropic-Cybersecurity-Skills · analyzing-slack-space-and-file-system-artifacts
Examine file system slack space, MFT entries, USN journal, and alternate data streams to recover hidden data and reconstruct file activity on NTFS volumes.
analyzing-disk-image-with-autopsy
mukul975/Anthropic-Cybersecurity-Skills · analyzing-disk-image-with-autopsy
Perform comprehensive forensic analysis of disk images using Autopsy to recover files, examine artifacts, and build investigation timelines.
extracting-browser-history-artifacts
mukul975/Anthropic-Cybersecurity-Skills · extracting-browser-history-artifacts
Extract and analyze browser history, cookies, cache, downloads, and bookmarks from Chrome, Firefox, and Edge for forensic evidence of user web activity.
performing-endpoint-forensics-investigation
mukul975/Anthropic-Cybersecurity-Skills · performing-endpoint-forensics-investigation
Performs digital forensics investigation on compromised endpoints including memory acquisition, disk imaging, artifact analysis, and timeline reconstruction. Use when investigating security incidents, collecting evidence for legal proceedings, or analyzing endpoint compromise scope. Activates for requests involving endpoint forensics, memory analysis, disk forensics, or incident investigation.
performing-cloud-log-forensics-with-athena
mukul975/Anthropic-Cybersecurity-Skills · performing-cloud-log-forensics-with-athena
Uses AWS Athena to query CloudTrail, VPC Flow Logs, S3 access logs, and ALB logs for forensic investigation. Covers CREATE TABLE DDL with partition projection, forensic SQL queries for detecting unauthorized access, data exfiltration, lateral movement, and privilege escalation. Use when investigating AWS security incidents or building cloud-native forensic workflows at scale.
analyzing-usb-device-connection-history
mukul975/Anthropic-Cybersecurity-Skills · analyzing-usb-device-connection-history
Investigate USB device connection history from Windows registry, event logs, and setupapi logs to track removable media usage and potential data exfiltration.
analyzing-prefetch-files-for-execution-history
mukul975/Anthropic-Cybersecurity-Skills · analyzing-prefetch-files-for-execution-history
Parse Windows Prefetch files to determine program execution history including run counts, timestamps, and referenced files for forensic investigation.
analyzing-linux-system-artifacts
mukul975/Anthropic-Cybersecurity-Skills · analyzing-linux-system-artifacts
Examine Linux system artifacts including auth logs, cron jobs, shell history, and system configuration to uncover evidence of compromise or unauthorized activity.
performing-mobile-device-forensics-with-cellebrite
mukul975/Anthropic-Cybersecurity-Skills · performing-mobile-device-forensics-with-cellebrite
Acquire and analyze mobile device data using Cellebrite UFED and open-source tools to extract communications, location data, and application artifacts.
analyzing-powershell-empire-artifacts
mukul975/Anthropic-Cybersecurity-Skills · analyzing-powershell-empire-artifacts
Detect PowerShell Empire framework artifacts in Windows event logs by identifying Base64 encoded launcher patterns, default user agents, staging URL structures, stager IOCs, and known Empire module signatures in Script Block Logging events.