Digital Forensics

zhaoxuya520/reverse-skill/skills/digital-forensics

by zhaoxuya520cab634bd855fNo license40K starsListed Oct 9, 2026Updated Oct 9, 2026Repository updated 2 weeks ago

Use for authorized digital forensics including memory dumps, disk timelines, PCAP investigation, artifact triage, and IR evidence preservation.

Instructions onlySecurity
AI-generated overview

Guides authorized digital forensics and incident-response artifact triage across memory, disk, host and network evidence.

What it does
This skill provides a structured workflow for authorized digital forensics and incident response: evidence preservation with hashing and chain-of-custody notes, memory analysis, host artifact review, and network investigation. It lists commands and tooling such as Volatility 3, tshark, Plaso, Timeline Explorer, Eric Zimmerman tools, Autopsy and FTK Imager, and points to a triage reference file. Outputs are case notes, timelines, preserved evidence records and graded IOCs.
When to use it
Use it when handling authorized forensic or incident-response work such as memory dumps, disk or E01 timelines, PCAP tracing, host artifact triage, or evidence preservation. It is intended for defensive investigation, not offensive scanning.
Requirements
Instructions only; no scripts are shipped. It assumes access to forensic tooling (Volatility 3, tshark, Plaso/Timeline Explorer, Eric Zimmerman tools, Autopsy/FTK Imager), read-only evidence copies, and authorization or an organizational IR mandate. It references sibling skills and a local triage reference file.

Digital Forensics & IR Artifacts

ACTION REQUIRED(读完后立刻执行)

  1. NOW: 读取 ../field-journal/precedent-pentest.md 或组织 IR 授权说明
  2. NOW: 确认是取证/溯源而非进攻性扫描
  3. NOW: 建立 case;证据只读副本优先(原始介质写保护)
  4. NEXT: tool-index;Volatility 等常手动
  5. ACT: 保全哈希 → 时间线 → 关键伪影

适用场景

  • 内存转储分析(Volatility 2/3)
  • 磁盘/ E01 / 落地文件时间线
  • PCAP 溯源与协议还原(可联合 protocol-reverse/)
  • 主机伪影:Prefetch、Shimcache、Event Log、浏览器历史
  • 应急响应 IOC 提炼(联合 malware-analysis/ / threat-hunting/)

工作流

1. 保全

text
□ 计算 SHA256;记录时区与采集命令□ 工作在副本上;原始只读□ chain of custody 备注写入 timeline

2. 内存

bash
vol -f mem.dmp windows.infovol -f mem.dmp windows.pslistvol -f mem.dmp windows.netscanvol -f mem.dmp windows.cmdline

3. 主机伪影

text
□ 事件日志:Security / PowerShell / Sysmon□ 持久化:Run 键、服务、计划任务、WMI□ 执行痕迹:Amcache、Prefetch、BAM

4. 网络

text
□ tshark 统计会话与 DNS□ 导出可疑流 → protocol-reverse 或 malware C2 分析

工具链

工具用途
Volatility 3内存
Timeline Explorer / Plaso超级时间线
tsharkPCAP
Eric Zimmerman 工具集Windows 伪影
Autopsy / FTK Imager磁盘

参考

  • references/forensics-triage.md
  • ../malware-analysis/ ../threat-hunting/ ../protocol-reverse/

路由上下文

上游: MASTER R25
下游: 恶意样本深挖 → malware-analysis;规则 → threat-hunting

任务完成自检

  • 是否保全哈希与副本策略?
  • 时间线是否可复核?
  • IOC 是否脱敏分级?
  • Checklist?

Source and attribution

Source:zhaoxuya520/reverse-skillinskills/digital-forensicsat commitcab634b

License: No license

Content belongs to its original authors. SourceWeft indexes it from a public repository.

Report or request removal