Ctf Crypto
ljagiello/ctf-skills
Provides cryptography attack techniques for CTF challenges. An agent skill from ljagiello/ctf-skills.
磁盘/文件系统取证:删除恢复、时间线、可疑文件定位. An agent skill from dslsdzc/rev-skills.
$ npx skills add dslsdzc/rev-skills --skill re-disk-forensics -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install dslsdzc/rev-skills re-disk-forensics --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/re-disk-forensics .claude/skills/re-disk-forensics && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "re-disk-forensics" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-disk-forensics into .claude/skills/re-disk-forensics/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-disk-forensics", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-disk-forensicsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add dslsdzc/rev-skills --skill re-disk-forensics -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install dslsdzc/rev-skills re-disk-forensics --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/re-disk-forensics .agents/skills/re-disk-forensics && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "re-disk-forensics" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-disk-forensics into .agents/skills/re-disk-forensics/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-disk-forensics", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add dslsdzc/rev-skills --skill re-disk-forensics -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install dslsdzc/rev-skills re-disk-forensics --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/re-disk-forensics .cursor/skills/re-disk-forensics && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "re-disk-forensics" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-disk-forensics into .cursor/skills/re-disk-forensics/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-disk-forensics", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/dslsdzc/rev-skills.git --path .claude/skills/re-disk-forensics--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add dslsdzc/rev-skills --skill re-disk-forensics -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install dslsdzc/rev-skills re-disk-forensics --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/re-disk-forensics .gemini/skills/re-disk-forensics && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "re-disk-forensics" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-disk-forensics into .gemini/skills/re-disk-forensics/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-disk-forensics", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install dslsdzc/rev-skills re-disk-forensicsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add dslsdzc/rev-skills --skill re-disk-forensics -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/re-disk-forensics .github/skills/re-disk-forensics && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "re-disk-forensics" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-disk-forensics into .github/skills/re-disk-forensics/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-disk-forensics", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add dslsdzc/rev-skills --skill re-disk-forensics -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install dslsdzc/rev-skills re-disk-forensics --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/re-disk-forensics .opencode/skills/re-disk-forensics && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "re-disk-forensics" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-disk-forensics into .opencode/skills/re-disk-forensics/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-disk-forensics", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
re-disk-forensics磁盘/文件系统取证:删除恢复、时间线、可疑文件定位. An agent skill from dslsdzc/rev-skills.
Re Disk Forensics is an agent skill from dslsdzc/rev-skills. 磁盘/文件系统取证:删除恢复、时间线、可疑文件定位。 触发词:磁盘取证、文件系统、删除恢复、时间线、ext4、NTFS
Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Digital forensics. It works with Linux, macOS and Homebrew. The repository describes itself as: 122 个逆向工程 AI 技能(可发布、跨平台):恶意软件分析 / 软件逆向 / 固件嵌入式 / 协议逆向 / 移动应用 / 脱壳反混淆 / 软件破解 / 漏洞挖掘 / 托管代码 / 取证情报 / CTF。 The licence is Apache-2.0.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit bd21db8. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
aptdnfbrewwingetsqlite3From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Re Disk Forensics loads about 1.9k tokens when it runs. Until then it costs about 19 tokens; SKILL.md has 459 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from dslsdzc/rev-skills at commit bd21db8, republished under its Apache-2.0 licence (© dslsdzc). 459 words, ~1,884 tokens.
.claude/skills/re-disk-forensics/SKILL.md (or your agent's skills folder).取证铁律:只读。本技能所有工具只读镜像文件、不挂载可写、不在原介质上写任何东西(见坑 1)。镜像获取与可疑对象提取的结果按 sha256 + 路径存档(取证要求可追溯,见 [[re-analyze/platform-tips]])。
apt install sleuthkitdnf install sleuthkitpacman -S sleuthkit(extra 仓库)brew install sleuthkitwinget install SleuthKit.Autopsy,内置 sleuthkit 工具)fls -h;mmls -h;tsk_recover -h;mactime -hapt install testdisk(photorec 在同一包内,官方文档确认无独立包)dnf install testdisk(photorec CLI 随包;GUI 版独立包 qphotorec)pacman -S testdisk(extra,photorec 随包)zypper install testdisk photorec(该发行版 photorec 为独立包)brew install testdisktestdisk /?;photorec /?apt install ewf-tools / Fedora dnf install ewf-tools / Arch pacman -S ewf-tools;验证: ewfacquire -Vapt install ntfs-3g / Fedora dnf install ntfs-3g / Arch pacman -S ntfs-3gmount -o ro,loop,noload ... 后 findmnt 输出包含 roapt install autopsy;Fedora: dnf install autopsy;Arch: pacman -S autopsy(AUR 或 extra);Windows: winget install SleuthKit.Autopsy;macOS: brew install --cask autopsy按顺序执行,每步产物(镜像/提取文件/时间线)存档 sha256 + 路径(供 [[re-ioc]] 报告引用)。
只读镜像获取(先存证后动手):
sha256sum /dev/sdX > evidence.sha256 # 原始介质哈希存证(分析前后复核)
dd if=/dev/sdX of=evidence.dd bs=4M conv=noerror,sync status=progress
sha256sum evidence.dd >> evidence.sha256 # 镜像哈希复核,与源哈希一致才继续blockdev --setro /dev/sdXdd if=/dev/sdX1 ... 只镜像目标分区;整盘镜像保留分区表与未分配空间(未分配空间常含残留证据,见步骤 5)ewfacquire /dev/sdX,内置校验与压缩)分区与文件系统识别(ext4 / NTFS / APFS):
file evidence.dd # 常见文件系统魔数初判
mmls evidence.dd # 分区表布局(含 start 扇区偏移)
fsstat -o <分区start> evidence.dd # 文件系统类型与元数据统计-o 参数是扇区偏移,直接填 mmls 输出的 start 列;loop 挂载则换算字节 offset=$((start*512))删除文件恢复(元数据法 + 雕刻法):
# 元数据法(保留文件名/路径/时间)—— sleuthkit
fls -r -o <分区start> evidence.dd # 全部文件,含 [DELETED]
fls -o <分区start> evidence.dd <inode> # 指定目录 inode 下文件
icat -o <分区start> evidence.dd <inode> > rec.bin # 按 inode 提取(含删除文件)
tsk_recover -o <分区start> evidence.dd out/ # 恢复已删除(未分配)文件——这是默认行为
tsk_recover -e -o <分区start> evidence.dd out_all/ # -e = 已分配 + 未分配全部导出(-a 则只导已分配)r/r 12345-128-1: 文件名 [DELETED]——行首 inode 号供 icat;未删除文件也可用 icat 精确提取(比挂载拷贝可控)testdisk evidence.dd # 交互: 恢复丢失分区表 / Advanced → Undelete
photorec /d <输出目录> evidence.dd # 雕刻: 按文件签名扫描恢复(无文件名,见坑 6)/d 指定输出目录时间线重建(fls -m → mactime):
fls -r -m / -o <分区start> evidence.dd > bodyfile # -m 生成 body file(挂载点写 /)
mactime -b bodyfile -d -z UTC > timeline.csv # -d CSV、-z 指定时区grep -i ',d,' timeline.csv(删除记录)可疑文件提取(未分配空间/隐藏分区):
# 未分配块(含删除文件残留、缓存、临时数据)
blkls -o <分区start> evidence.dd > unallocated.bin
strings -n 8 unallocated.bin | grep -iE 'key|password|flag|http' | head -50
# 分区表空隙(slack space)/隐藏分区: 按 mmls 相邻分区起止手工截取
dd if=evidence.dd of=gap.bin bs=512 skip=$((A_end+1)) count=$((B_start-A_end-1)) # mmls 的 End 是含端点的末扇区(Length=End-Start+1);两分区之间的空白 = A_end+1 .. B_start-1。更省事:直接用 mmls 列出的 Unallocated 项 Start/Lengthsqlite3 CLI 只读模式(sqlite3 -readonly)、页级解析脚本(python 按页结构遍历)mount 默认可写(ext4/NTFS 挂载会重放日志、更新访问时间),或在原设备上直接跑了恢复工具;对策——镜像一律 mount -o ro,loop,noexec,nodev,nosuid,ext4 加 noload、NTFS 用 ntfs-3g -o ro,recover=no 跳过日志重放(见坑 3);分析前 sha256 存证、分析后复核;物理盘用写保护器或 blockdev --setro;只读数据尽量用 sleuthkit 工具(fsstat/fls/icat 只解析不写)而非挂载dislocker 挂载)② 用户密码/恢复密钥(BitLocker 48 位恢复密钥、FileVault 恢复密钥、LUKS passphrase)③ 未加密的启动分区(UEFI/Boot 分区不加密,可提取启动链证据);工具: dislocker(BitLocker)、cryptsetup luksOpen(LUKS);拿不到密钥则该镜像只能做非内容取证(分区结构/引导链),并如实标注局限noload(ext4)/ recover=no(ntfs-3g);镜像直接存两份(原始 + 工作副本),分析在副本上做,原始镜像永不挂载© dslsdzc, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .claude/skills/re-disk-forensics of dslsdzc/rev-skills.
Open the folder on GitHubat commit bd21db8
Re Disk Forensics next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Re Disk Forensics this skilldslsdzc/rev-skills | 125 | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | |
| Ctf Cryptoljagiello/ctf-skills | 3.4k | — | ~11k | Automated safety check: Notes | MIT | |
| Forensics OsqueryAgentSecOps/SecOpsAgentKit | 220 | 1 repos | ~4.9k | Automated safety check: Notes | Custom licence | |
| Performing Memory Forensics With Volatility3 Pluginsmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~2.1k | Automated safety check: Pass | Apache-2.0 | |
| Analyzing Memory Dumps With Volatilitymukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | |
| Gearcoleco Debuggingdrhelius/Gearcoleco | 141 | — | ~3.5k | Automated safety check: Pass | GPL-3.0 |
ljagiello/ctf-skills
Provides cryptography attack techniques for CTF challenges. An agent skill from ljagiello/ctf-skills.
AgentSecOps/SecOpsAgentKit
SQL-powered forensic investigation and system interrogation using osquery to query operating systems as relational databases.
mukul975/Anthropic-Cybersecurity-Skills
Analyze memory dumps using Volatility3 plugins to detect injected code, rootkits, credential theft, and malware artifacts in Windows, Linux, and macOS memory images.
mukul975/Anthropic-Cybersecurity-Skills
Analyzes RAM memory dumps from compromised systems using the Volatility framework to identify malicious processes, injected code, network connections, loaded modules, and extracted credentials.
drhelius/Gearcoleco
Debug and trace ColecoVision and Super Game Module games using the Gearcoleco emulator MCP server.
wysaid/CameraCapture
Install or use the ccap CLI for camera capture, webcam inspection, device listing, frame capture, and video metadata.
dslsdzc/rev-skills
威胁归因方法论:钻石模型、基础设施图谱、置信度分级与归因报告. An agent skill from dslsdzc/rev-skills.
dslsdzc/rev-skills
Captures an analyzable sample from a live system when the target leaves no file on disk, by finding abnormal executable memory and the execution context that reached it.
dslsdzc/rev-skills
函数式语言运行时逆向(Haskell/OCaml):闭包/堆对象模型、调用约定、数据流优先策略. An agent skill from dslsdzc/rev-skills.
dslsdzc/rev-skills
虚拟化逆向:VT-x/SVM、hypervisor 检测、VMCS/EPT 分析, 以及 Xen / QNX Hypervisor / Jailhouse / ACRN / Bao / Hyper-V·VMBus / XtratuM / LynxSecure / Quest-V 的分区与 vdev 语义。
dslsdzc/rev-skills
射频逆向:信号采集、频谱分析、解调、帧同步与协议恢复、重放. An agent skill from dslsdzc/rev-skills.
dslsdzc/rev-skills
UEFI/BIOS 固件:SEC/PEI/DXE/BDS 阶段判定、DXE 驱动、UEFI 模块、bootkit. An agent skill from dslsdzc/rev-skills.
Categories
磁盘/文件系统取证:删除恢复、时间线、可疑文件定位. An agent skill from dslsdzc/rev-skills. Re Disk Forensics is an agent skill from dslsdzc/rev-skills.
Re Disk Forensics fits situations like: tasks that involve Digital forensics.
Run `npx skills add dslsdzc/rev-skills --skill re-disk-forensics -a claude-code`. Or copy the skill folder (.claude/skills/re-disk-forensics in dslsdzc/rev-skills) into .claude/skills/re-disk-forensics in your project. Claude Code loads it when a task matches its description.
Run `npx skills add dslsdzc/rev-skills --skill re-disk-forensics -a codex`. Or copy the skill folder (.claude/skills/re-disk-forensics in dslsdzc/rev-skills) into .agents/skills/re-disk-forensics in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add dslsdzc/rev-skills --skill re-disk-forensics -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/re-disk-forensics, .gemini/skills/re-disk-forensics, .github/skills/re-disk-forensics and .opencode/skills/re-disk-forensics in your project.
Going by SKILL.md and its folder, Re Disk Forensics needs the command-line tools its instructions call (apt, dnf, brew, winget and sqlite3). Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Re Disk Forensics is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.9k tokens (SKILL.md is roughly 7.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Re Disk Forensics: Ctf Crypto (ljagiello/ctf-skills, 3.4k stars), Forensics Osquery (AgentSecOps/SecOpsAgentKit, 220 stars), Performing Memory Forensics With Volatility3 Plugins (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Analyzing Memory Dumps With Volatility (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
dslsdzc (a GitHub user) maintains it in dslsdzc/rev-skills, which has 125 GitHub stars. The repository holds 41 skills in this directory. The repository was last updated on October 5, 2026.
Source: dslsdzc/rev-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.