Search
Digital forensics
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Provides malware analysis and network traffic techniques for CTF challenges. | ljagiello/ | 3.4k | 1 repo | ~2.1k | Automated safety check: Notes | MIT | 25 days ago |
| 2 | Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution. | mukul975/ | 34k | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 3 | Supply chain investigation, evidence recovery, and forensic analysis for GitHub repositories. | Tommy-yw/ | 546 | 3 repos | ~5k | Automated safety check: Pass | MIT | 4 mo ago |
| 4 | Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution. | mukul975/ | 34k | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 5 | Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison. | mukul975/ | 34k | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 6 | A skill your agent uses when asked to investigate Conditional Access policy changes, sign-in failures related to CA policies (error codes 53000, 50074, 530032), or suspected policy… | SCStelz/ | 249 | — | ~3.8k | Automated safety check: Pass | MIT | 2 days ago |
| 7 | 7.Dfir Digital forensics and incident response - Windows event log analysis, PCAP forensics, filesystem artifact analysis, AD attack detection, and timeline correlation. | transilienceai/ | 562 | — | ~1.5k | Automated safety check: Pass | MIT | 2 mo ago |
| 8 | Status-first routing, bounded evidence collection, and safety guidance for issue-graph. | vercel-labs/ | 125 | — | ~2.6k | Automated safety check: Pass | Apache-2.0 | 7 days ago |
| 9 | Guides authorized packet capture and analysis with TShark, Wireshark's command-line tool, for security investigations, malware detection and forensic examination of network traffic. | AgentSecOps/ | 220 | 1 repo | ~4.8k | Automated safety check: Notes | Unknown | 5 mo ago |
| 10 | Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping. | mukul975/ | 34k | — | ~2.7k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 11 | Captures an analyzable sample from a live system when the target leaves no file on disk, by finding abnormal executable memory and the execution context that reached it. | dslsdzc/ | 125 | — | ~2k | Automated safety check: Pass | Apache-2.0 | 3 days ago |
| 12 | Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic. | mukul975/ | 34k | — | ~2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 13 | 13.Investigate Systematic debugging with Iron Law methodology. An agent skill from catlog22/Claude-Code-Workflow. | catlog22/ | 2.1k | — | ~1.1k | Automated safety check: Notes | MIT | 3 mo ago |
| 14 | A skill your agent uses for authorized digital forensics including memory dumps, disk timelines, PCAP investigation, artifact triage, and IR evidence preservation. | zhaoxuya520/ | 40k | 2 repos | ~389 | Automated safety check: Warn | MIT | 16 days ago |
| 15 | Reconstructs folder browsing history from Windows Shellbag registry data using SBECmd and Shellbags Explorer, even for folders that were later deleted. | mukul975/ | 34k | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 16 | Amazon brand protection toolkit. An agent skill from nexscope-ai/eCommerce-Skills. | nexscope-ai/ | 1.1k | — | ~770 | Automated safety check: Pass | MIT | 1 mo ago |
| 17 | Black box flight recorder for the server. An agent skill from bolivian-peru/os-moda. | bolivian-peru/ | 119 | — | ~624 | Automated safety check: Pass | Apache-2.0 | 3 mo ago |
| 18 | A skill your agent uses when responding to or forensically investigating an incident — triage acquisition (Velociraptor/KAPE), Volatility 3 memory forensics, Chainsaw/Hayabusa EVTX timelining… | hypnguyen1209/ | 386 | — | ~2.5k | Automated safety check: Pass | MIT | 10 days ago |
| 19 | Diagnostics-only BGP troubleshooting patterns for neighbor state, route exchange, prefix policy, AS path inspection, and safe evidence collection. | affaan-m/ | 275k | 1 repo | ~1.4k | Automated safety check: Pass | MIT | 3 days ago |
| 20 | Provides digital forensics and signal analysis techniques for CTF challenges. | ljagiello/ | 3.4k | — | ~9.2k | Automated safety check: Warn | MIT | 25 days ago |
| 21 | A skill your agent uses when asked to trace authentication flows, analyze SessionId chains, investigate token reuse vs interactive MFA, or assess geographic anomalies in sign-ins. | SCStelz/ | 249 | — | ~8.6k | Automated safety check: Pass | MIT | 2 days ago |
| 22 | Debug complex issues using competing hypotheses with parallel investigation, evidence collection, and root cause arbitration. | wshobson/ | 40k | 1 repo | ~1.2k | Automated safety check: Pass | MIT | 3 days ago |
| 23 | Analyze disk images, file systems, and memory captures for digital evidence recovery in forensic investigations and CTF challenges. | briiirussell/ | 413 | — | ~1.5k | Automated safety check: Notes | MIT | 4 mo ago |
| 24 | Judge product usability and evidence quality. An agent skill from aryaniyaps/lamina. | aryaniyaps/ | 115 | — | ~432 | Automated safety check: Pass | Apache-2.0 | 7 days ago |
| 25 | Build collaborative forensic incident timelines using Timesketch to ingest, normalize, and analyze multi-source event data (including Plaso output) for attack chain reconstruction and investigation… | mukul975/ | 34k | — | ~2.4k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 26 | SQL-powered forensic investigation and system interrogation using osquery to query operating systems as relational databases. | AgentSecOps/ | 220 | 1 repo | ~4.9k | Automated safety check: Notes | Unknown | 5 mo ago |
| 27 | Endpoint visibility, digital forensics, and incident response using Velociraptor Query Language (VQL) for evidence collection and threat hunting at scale. | AgentSecOps/ | 220 | 1 repo | ~3.1k | Automated safety check: Pass | Unknown | 5 mo ago |
| 28 | Performs digital forensics investigation on compromised endpoints including memory acquisition, disk imaging, artifact analysis, and timeline reconstruction. | mukul975/ | 34k | — | ~2k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 29 | Perform forensic analysis of network packet captures (PCAP/PCAPNG) using Wireshark, tshark, and tcpdump to reconstruct network communications, extract transferred files, identify malicious traffic… | mukul975/ | 34k | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 30 | Automates SOC 2 Type II audit preparation including gap assessment against AICPA Trust Services Criteria (CC1-CC9), evidence collection from cloud providers and identity systems, control testing… | mukul975/ | 34k | — | ~2.7k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 31 | Authorized digital forensics: memory dumps, disk timelines, PCAP investigation, artifact triage, and incident-response evidence preservation. | sickn33/ | 47k | 1 repo | ~495 | Automated safety check: Pass | MIT | yesterday |
| 32 | Perform comprehensive forensic analysis of raw (dd), E01, or AFF disk images with Autopsy and The Sleuth Kit, recovering deleted files, examining metadata and embedded artifacts, keyword searching… | mukul975/ | 34k | — | ~2.7k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 33 | Performs Linux memory acquisition using LiME (Linux Memory Extractor) kernel module and analysis with Volatility 3 framework. | mukul975/ | 34k | — | ~631 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 34 | Parse Microsoft Outlook PST and OST files using libpff and pst-utils to extract message content, headers, attachments, deleted items, and MAPI metadata, including recovery of items from the… | mukul975/ | 34k | — | ~3.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 35 | Parses the Windows Amcache.hve registry hive with Eric Zimmerman's AmcacheParser and Timeline Explorer to extract evidence of program execution, application installation, and driver loading… | mukul975/ | 34k | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 36 | Analyzes Windows Security, System, and Sysmon event logs in Splunk to detect authentication attacks, privilege escalation, persistence mechanisms, and lateral movement using SPL queries mapped to… | mukul975/ | 34k | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 37 | Parse Windows LNK shortcut files to extract target paths, MAC timestamps, volume serial numbers, and machine identifiers for forensic timeline reconstruction. | mukul975/ | 34k | — | ~3.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 38 | Extract and analyze Windows Registry hives with tools like RegRipper and Registry Explorer to uncover user activity, installed software, autostart/persistence entries, and evidence of system… | mukul975/ | 34k | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 39 | Generate forensic super-timelines with Plaso's log2timeline.py, pinfo.py, psort.py, and psteal.py CLI tools (fusing file-system MACB, registry, EVTX, browser history, prefetch, LNK, and more), then… | mukul975/ | 34k | — | ~1.9k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 40 | Detects rootkit presence on compromised systems by identifying hidden processes, hooked system calls, modified kernel structures, and covert network connections using Volatility memory forensics… | mukul975/ | 34k | — | ~3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 41 | Extracts cached credentials, password hashes, Kerberos tickets, and authentication tokens from Windows memory dumps using Volatility 3, Mimikatz, and pypykatz. | mukul975/ | 34k | — | ~3.4k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 42 | Collect and analyze cloud forensic evidence using AWS CLI, Azure CLI, or gcloud to snapshot volumes, capture instance metadata and security group configurations, and preserve cloud-native logs… | mukul975/ | 34k | — | ~3.4k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 43 | Investigate AWS account compromise by querying CloudTrail with boto3's LookupEvents or AWS Athena SQL over S3-delivered logs, filtering on suspicious user agents, source IPs, and event names to… | mukul975/ | 34k | — | ~845 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 44 | Uses AWS Athena to query CloudTrail, VPC Flow Logs, S3 access logs, and ALB logs for forensic investigation. | mukul975/ | 34k | — | ~3.7k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 45 | Conduct disk forensics investigations using forensic imaging, file system analysis, and timeline reconstruction, with tools such as FTK Imager, Autopsy, and The Sleuth Kit, for evidence acquisition… | mukul975/ | 34k | — | ~2.7k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 46 | Investigates insider threat incidents involving employees, contractors, or trusted partners who misuse authorized access to steal data, sabotage systems, or violate security policies, combining… | mukul975/ | 34k | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 47 | Executes a structured ransomware incident response from detection through containment, forensic analysis, decryption assessment, recovery, and post-incident hardening, covering ransom negotiation… | mukul975/ | 34k | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 48 | A skill your agent uses when a security incident has been detected or declared and needs classification, triage, escalation path determination, and forensic evidence collection. | alirezarezvani/ | 28k | — | ~3.8k | Automated safety check: Pass | MIT | 1 mo ago |