Agent skill

Re Disk Forensics

by dslsdzc in dslsdzc/rev-skills

磁盘/文件系统取证:删除恢复、时间线、可疑文件定位. An agent skill from dslsdzc/rev-skills.

Apache-2.0Auto-check passedSecurity

Install Re Disk Forensics

skills CLI
$ npx skills add dslsdzc/rev-skills --skill re-disk-forensics -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install dslsdzc/rev-skills re-disk-forensics --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/re-disk-forensics .claude/skills/re-disk-forensics && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
re-disk-forensics
GitHub stars
125
Token cost
~1.9k tokens
SKILL.md length
459 words
Files
1
Skills in repo
41
Repo updated
First seen
Licence
Apache-2.0

At a glance

磁盘/文件系统取证:删除恢复、时间线、可疑文件定位. An agent skill from dslsdzc/rev-skills.

  • Works in 5 steps: 只读镜像获取(先存证后动手) → 分区与文件系统识别(ext4 / NTFS / APFS) → 删除文件恢复(元数据法 + 雕刻法) → …
  • Tasks that involve Digital forensics
  • SKILL.md covers 何时使用 / 何时不用, 工具准备, 操作步骤 and 数据库文件格式, plus 2 more sections
  • Calls apt, dnf and brew

What it does

Re Disk Forensics is an agent skill from dslsdzc/rev-skills. 磁盘/文件系统取证:删除恢复、时间线、可疑文件定位。 触发词:磁盘取证、文件系统、删除恢复、时间线、ext4、NTFS

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Digital forensics. It works with Linux, macOS and Homebrew. The repository describes itself as: 122 个逆向工程 AI 技能(可发布、跨平台):恶意软件分析 / 软件逆向 / 固件嵌入式 / 协议逆向 / 移动应用 / 脱壳反混淆 / 软件破解 / 漏洞挖掘 / 托管代码 / 取证情报 / CTF。 The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Digital forensics

Example prompts

  • “/re-disk-forensics”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. 只读镜像获取(先存证后动手)
  2. 分区与文件系统识别(ext4 / NTFS / APFS)
  3. 删除文件恢复(元数据法 + 雕刻法)
  4. 时间线重建(fls -m → mactime)
  5. 可疑文件提取(未分配空间/隐藏分区)

What it can do on your machine

Read from SKILL.md and the folder at commit bd21db8. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • apt
    • dnf
    • brew
    • winget
    • sqlite3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Re Disk Forensics loads about 1.9k tokens when it runs. Until then it costs about 19 tokens; SKILL.md has 459 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~19
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from dslsdzc/rev-skills at commit bd21db8, republished under its Apache-2.0 licence (© dslsdzc). 459 words, ~1,884 tokens.

Download SKILL.mdSave it as .claude/skills/re-disk-forensics/SKILL.md (or your agent's skills folder).
name
re-disk-forensics
description
磁盘/文件系统取证:删除恢复、时间线、可疑文件定位。 触发词:磁盘取证、文件系统、删除恢复、时间线、ext4、NTFS
capabilities
disk-forensics

磁盘取证与文件系统分析

何时使用 / 何时不用

  • 用:拿到磁盘镜像(dd / E01)或介质做取证——删除文件恢复、时间线重建、可疑文件/残留数据定位
  • 用:事件响应需要"介质上发生过什么"(删了什么、什么时候写的、留了什么痕迹)
  • 用:分区丢失/损坏后的分区表重建与文件抢救(testdisk)
  • 不用:内存取证(那是 [[re-mem-forensics]],与磁盘取证并列的另一个取证分支)
  • 不用:普通文件系统挂载使用(那要可写挂载;取证一律只读,见坑 1)
  • 不用:加密卷且无密钥——先找密钥(见坑 2)

工具准备

取证铁律:只读。本技能所有工具只读镜像文件、不挂载可写、不在原介质上写任何东西(见坑 1)。镜像获取与可疑对象提取的结果按 sha256 + 路径存档(取证要求可追溯,见 [[re-analyze/platform-tips]])。

sleuthkit —— 取证分析主力(fls/icat/tsk_recover/mmls/fsstat/blkls)
  • Debian/Ubuntu: apt install sleuthkit
  • Fedora: dnf install sleuthkit
  • Arch: pacman -S sleuthkit(extra 仓库)
  • macOS: brew install sleuthkit
  • Windows: WSL 内 Linux 版优先(见 [[re-analyze/platform-tips]] WSL 分支);GUI 用 Autopsy(winget install SleuthKit.Autopsy,内置 sleuthkit 工具)
  • 验证: fls -h;mmls -h;tsk_recover -h;mactime -h
testdisk / photorec —— 分区修复与文件雕刻(cgsecurity)
  • Debian/Ubuntu: apt install testdisk(photorec 在同一包内,官方文档确认无独立包)
  • Fedora: dnf install testdisk(photorec CLI 随包;GUI 版独立包 qphotorec)
  • Arch: pacman -S testdisk(extra,photorec 随包)
  • openSUSE: zypper install testdisk photorec(该发行版 photorec 为独立包)
  • macOS: brew install testdisk
  • Windows: WSL 内 Linux 版(chocolatey 上 testdisk 包极旧,不推荐)
  • 验证: testdisk /?;photorec /?
dd / ewf-tools —— 镜像获取
  • dd: coreutils 自带(Linux/macOS/WSL 均可用)
  • ewf-tools(E01 证据格式,带校验块): Debian/Ubuntu apt install ewf-tools / Fedora dnf install ewf-tools / Arch pacman -S ewf-tools;验证: ewfacquire -V
  • Windows: 只读镜像工具 FTK Imager(GUI,exterro 官网免费版)或 WSL 内 Linux 版
只读挂载 —— loop + ro(需要直接读文件内容时)
  • mount 内置(util-linux);NTFS 需 ntfs-3g: Debian/Ubuntu apt install ntfs-3g / Fedora dnf install ntfs-3g / Arch pacman -S ntfs-3g
  • 验证: mount -o ro,loop,noload ... 后 findmnt 输出包含 ro
autopsy —— 可选 GUI(团队/可视化)
  • Debian/Ubuntu: apt install autopsy;Fedora: dnf install autopsy;Arch: pacman -S autopsy(AUR 或 extra);Windows: winget install SleuthKit.Autopsy;macOS: brew install --cask autopsy

操作步骤

按顺序执行,每步产物(镜像/提取文件/时间线)存档 sha256 + 路径(供 [[re-ioc]] 报告引用)。

  1. 只读镜像获取(先存证后动手):

    sh
    sha256sum /dev/sdX > evidence.sha256     # 原始介质哈希存证(分析前后复核)
    dd if=/dev/sdX of=evidence.dd bs=4M conv=noerror,sync status=progress
    sha256sum evidence.dd >> evidence.sha256 # 镜像哈希复核,与源哈希一致才继续
    • 物理盘优先用写保护器(USB write-blocker);软件写保护 blockdev --setro /dev/sdX
    • 分区镜像: dd if=/dev/sdX1 ... 只镜像目标分区;整盘镜像保留分区表与未分配空间(未分配空间常含残留证据,见步骤 5)
    • 证据格式: raw dd 最通用;长期保存用 E01(ewfacquire /dev/sdX,内置校验与压缩)
    • 已有多份镜像(事件响应常用方案)时直接进入步骤 2,别重复取
  2. 分区与文件系统识别(ext4 / NTFS / APFS):

    sh
    file evidence.dd                          # 常见文件系统魔数初判
    mmls evidence.dd                          # 分区表布局(含 start 扇区偏移)
    fsstat -o <分区start> evidence.dd         # 文件系统类型与元数据统计
    • sleuthkit 的 -o 参数是扇区偏移,直接填 mmls 输出的 start 列;loop 挂载则换算字节 offset=$((start*512))
    • ext4: fsstat 输出 superblock/mgroup;NTFS: 输出 $MFT 位置;APFS: mmls 显示 Apple_APFS 容器分区(APFS 内部卷需要 apfs 工具,sleuthkit 对 APFS 支持有限,必要时用 macOS 本机工具)
    • 无分区表(整盘文件系统 / 隐藏分区 / 被删分区表)→ mmls 无输出:直接对镜像 fsstat;分区表重建用 testdisk(步骤 3)
    • 识别失败且熵高 → 加密卷(BitLocker/FileVault/LUKS),见坑 2
  3. 删除文件恢复(元数据法 + 雕刻法):

    sh
    # 元数据法(保留文件名/路径/时间)—— sleuthkit
    fls -r -o <分区start> evidence.dd                       # 全部文件,含 [DELETED]
    fls -o <分区start> evidence.dd <inode>                  # 指定目录 inode 下文件
    icat -o <分区start> evidence.dd <inode> > rec.bin       # 按 inode 提取(含删除文件)
    tsk_recover -o <分区start> evidence.dd out/             # 恢复已删除(未分配)文件——这是默认行为
    tsk_recover -e -o <分区start> evidence.dd out_all/      # -e = 已分配 + 未分配全部导出(-a 则只导已分配)
    • fls 输出 r/r 12345-128-1: 文件名 [DELETED]——行首 inode 号供 icat;未删除文件也可用 icat 精确提取(比挂载拷贝可控)
    • 删除恢复结果不是 100%(SSD TRIM/覆写),见坑 5
    • 分区丢失/损坏、元数据法失效 → testdisk / photorec(雕刻):
      sh
      testdisk evidence.dd          # 交互: 恢复丢失分区表 / Advanced → Undelete
      photorec /d <输出目录> evidence.dd   # 雕刻: 按文件签名扫描恢复(无文件名,见坑 6)
    • photorec 恢复类型可交互过滤(只雕刻目标扩展名,缩小结果集);/d 指定输出目录
  4. 时间线重建(fls -m → mactime):

    sh
    fls -r -m / -o <分区start> evidence.dd > bodyfile      # -m 生成 body file(挂载点写 /)
    mactime -b bodyfile -d -z UTC > timeline.csv           # -d CSV、-z 指定时区
    • 时间线回答"什么时候创建/修改/删除/访问"——找异常窗口(凌晨批量写、删除+复制组合、反常的访问时间)
    • 时间戳可被伪造(timestomp),见坑 4——时间线要与其他来源(USN Journal、系统日志、[[re-mem-forensics]] 内存时间线)交叉验证
    • CSV 里按 MAC 时间过滤删除动作: grep -i ',d,' timeline.csv(删除记录)
  5. 可疑文件提取(未分配空间/隐藏分区):

    sh
    # 未分配块(含删除文件残留、缓存、临时数据)
    blkls -o <分区start> evidence.dd > unallocated.bin
    strings -n 8 unallocated.bin | grep -iE 'key|password|flag|http' | head -50
    # 分区表空隙(slack space)/隐藏分区: 按 mmls 相邻分区起止手工截取
    dd if=evidence.dd of=gap.bin bs=512 skip=$((A_end+1)) count=$((B_start-A_end-1))   # mmls 的 End 是含端点的末扇区(Length=End-Start+1);两分区之间的空白 = A_end+1 .. B_start-1。更省事:直接用 mmls 列出的 Unallocated 项 Start/Length
    • 未分配空间是"删除≠消失"的主战场:凭据/密钥/URL/文档残片常留在那里
    • 被删除/隐藏分区: testdisk 扫描重建分区表项后,把重建分区按步骤 3 流程恢复文件
    • 提取对象(文件/残片)先算 sha256 再分析;可疑二进制转 [[re-binary-core]] 深挖,敏感串进 [[re-ioc]] IOC 列表
Show full SKILL.md (136 more words)Show less

数据库文件格式

  • SQLite 结构:页头(page header 字段)、btree 页(interior/leaf 类型)、记录格式(varint 长度编码 / 类型码)、溢出页(大字段跨页)
  • WAL 恢复:WAL 文件帧解析(未 checkpoint 的事务)、checkpoint 边界判定(恢复点)
  • 取证应用:浏览器/App 数据库——删除记录恢复(freelist 页残留)、未提交事务提取(WAL 内)
  • 工具:sqlite3 CLI 只读模式(sqlite3 -readonly)、页级解析脚本(python 按页结构遍历)

跨域联合

  • [[re-forensics]]:本技能是该网关的磁盘侧取证分支(内存侧为 [[re-mem-forensics]])——网关选择树按"内存 vs 磁盘"分派
  • [[re-mem-forensics]]:并列的取证分支——内存残留与磁盘证据互证(进程行为 ↔ 文件落地);BitLocker 密钥可先从内存取证插件拿(再回本技能解密卷)
  • [[re-ti]]:提取对象(哈希/域名/IP)做情报查询
  • [[re-ioc]]:磁盘证据(文件/时间线/残留数据)汇总成 IOC 与报告证据段
  • [[re-binary-core]]:提取的可疑二进制/脚本深挖([[re-ghidra]] / [[re-ida]])
  • [[re-crypto-keys]] / [[re-crypto-decrypt]]:加密卷密钥提取(BitLocker/LUKS)与加密文件解密
  • [[re-firmware]]:固件/嵌入式存储镜像同样按"磁盘镜像"流程处理(binwalk 解包层)
  • [[re-memdump]]:内存转储是磁盘取证的上游佐证(密钥/凭据/执行痕迹,默认转储优先)
  • 引用 [[re-analyze/platform-tips]] WSL 分支(Windows 盘镜像在 WSL 内用 Linux 取证工具)与取证证据链要求

常见坑与陷阱

  • 写操作污染证据(必须只读):现象——分析完镜像哈希对不上、文件系统状态前后不一致、报告无法自证;原因——mount 默认可写(ext4/NTFS 挂载会重放日志、更新访问时间),或在原设备上直接跑了恢复工具;对策——镜像一律 mount -o ro,loop,noexec,nodev,nosuid,ext4 加 noload、NTFS 用 ntfs-3g -o ro,recover=no 跳过日志重放(见坑 3);分析前 sha256 存证、分析后复核;物理盘用写保护器或 blockdev --setro;只读数据尽量用 sleuthkit 工具(fsstat/fls/icat 只解析不写)而非挂载
  • 加密卷(BitLocker/FileVault/LUKS):现象——fsstat/testdisk 报"无法识别文件系统",扇区全是高熵;原因——全卷加密,无密钥看不到内容;对策——密钥路径: ① 系统运行时的内存转储取密钥([[re-mem-forensics]] 的 Bitlocker FVEK 扫描插件 → dislocker 挂载)② 用户密码/恢复密钥(BitLocker 48 位恢复密钥、FileVault 恢复密钥、LUKS passphrase)③ 未加密的启动分区(UEFI/Boot 分区不加密,可提取启动链证据);工具: dislocker(BitLocker)、cryptsetup luksOpen(LUKS);拿不到密钥则该镜像只能做非内容取证(分区结构/引导链),并如实标注局限
  • 文件系统日志干扰:现象——fls 看到的文件状态与分析时不一致(文件"回滚"到旧状态),或挂载后镜像哈希变化;原因——ext4 jbd2 / NTFS 日志在挂载时被重放,未提交事务被写回;对策——只读挂载必须带 noload(ext4)/ recover=no(ntfs-3g);镜像直接存两份(原始 + 工作副本),分析在副本上做,原始镜像永不挂载
  • 时间戳伪造(timestomp):现象——时间线里成批文件的时间戳完全一致或明显不合理(如删除时间早于创建时间、全部改为同一时刻);原因——攻击者/样本用 timestomp 类手法改写 MFT/inode 时间戳([[re-malware]] 常见收尾动作);对策——交叉验证: NTFS 的 USN Journal(记录了真实变更序列)、ext4 的访问时间 vs crtime、系统日志、[[re-mem-forensics]] 内存时间线;发现伪造行为本身就是重要取证结论,写进报告而不是当脏数据滤掉
  • 删除 ≠ 可恢复(SSD TRIM/覆写):现象——fls 列出一堆 [DELETED] 但 icat 读出来全 0 或取不到;原因——SSD TRIM 已擦除物理块、数据被后续写入覆盖、NTFS 压缩/加密文件;对策——先确认介质类型(HDD/SSD)与删除时间窗口(越早恢复概率越高);未分配空间走 blkls 看是否有残留,全 0 就如实报告"已被擦除"
  • photorec 雕刻误报:现象——恢复出大量"文件"但打不开/内容与扩展名不符;原因——签名雕刻只认文件头,真实文件碎片化或被覆写后拼接出假文件;对策——交互菜单按文件类型过滤(只恢复目标类型)、优先验证小文件与关键类型、恢复结果抽查内容并算 sha256 入库([[re-ioc]])

© dslsdzc, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/re-disk-forensics of dslsdzc/rev-skills.

Open the folder on GitHubat commit bd21db8

Compare with similar skills

Re Disk Forensics next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Re Disk Forensics compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Re Disk Forensics this skilldslsdzc/rev-skills125—~1.9kAutomated safety check: PassApache-2.0
Ctf Cryptoljagiello/ctf-skills3.4k—~11kAutomated safety check: NotesMIT
Forensics OsqueryAgentSecOps/SecOpsAgentKit2201 repos~4.9kAutomated safety check: NotesCustom licence
Performing Memory Forensics With Volatility3 Pluginsmukul975/Anthropic-Cybersecurity-Skills34k—~2.1kAutomated safety check: PassApache-2.0
Analyzing Memory Dumps With Volatilitymukul975/Anthropic-Cybersecurity-Skills34k—~2.9kAutomated safety check: PassApache-2.0
Gearcoleco Debuggingdrhelius/Gearcoleco141—~3.5kAutomated safety check: PassGPL-3.0

Similar skills

  • Ctf Crypto

    ljagiello/ctf-skills

    Provides cryptography attack techniques for CTF challenges. An agent skill from ljagiello/ctf-skills.

    3.4k GitHub stars~11k tokensUpdated 24 days ago
    SecurityAuto-check: notes
  • Forensics Osquery

    AgentSecOps/SecOpsAgentKit

    SQL-powered forensic investigation and system interrogation using osquery to query operating systems as relational databases.

    220 GitHub starsUsed in 1 repo~4.9k tokens
    SecurityAuto-check: notes
  • Performing Memory Forensics With Volatility3 Plugins

    mukul975/Anthropic-Cybersecurity-Skills

    Analyze memory dumps using Volatility3 plugins to detect injected code, rootkits, credential theft, and malware artifacts in Windows, Linux, and macOS memory images.

    34k GitHub stars~2.1k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Analyzing Memory Dumps With Volatility

    mukul975/Anthropic-Cybersecurity-Skills

    Analyzes RAM memory dumps from compromised systems using the Volatility framework to identify malicious processes, injected code, network connections, loaded modules, and extracted credentials.

    34k GitHub stars~2.9k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Gearcoleco Debugging

    drhelius/Gearcoleco

    Debug and trace ColecoVision and Super Game Module games using the Gearcoleco emulator MCP server.

    141 GitHub stars~3.5k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Ccap

    wysaid/CameraCapture

    Install or use the ccap CLI for camera capture, webcam inspection, device listing, frame capture, and video metadata.

    191 GitHub stars~1.4k tokensUpdated 3 mo ago
    MobileAuto-check passed

More from dslsdzc/rev-skills

All 41 skills in this repo
  • Re Attribution

    dslsdzc/rev-skills

    威胁归因方法论:钻石模型、基础设施图谱、置信度分级与归因报告. An agent skill from dslsdzc/rev-skills.

    125 GitHub starsUsed in 1 repo~1.1k tokens
    Auto-check passed
  • Captures an analyzable sample from a live system when the target leaves no file on disk, by finding abnormal executable memory and the execution context that reached it.

    125 GitHub stars~2k tokensUpdated 3 days ago
    Auto-check passed
  • Re Fp Runtime

    dslsdzc/rev-skills

    函数式语言运行时逆向(Haskell/OCaml):闭包/堆对象模型、调用约定、数据流优先策略. An agent skill from dslsdzc/rev-skills.

    125 GitHub starsUsed in 1 repo~1.4k tokens
    Auto-check passed
  • Re Hypervisor

    dslsdzc/rev-skills

    虚拟化逆向:VT-x/SVM、hypervisor 检测、VMCS/EPT 分析, 以及 Xen / QNX Hypervisor / Jailhouse / ACRN / Bao / Hyper-V·VMBus / XtratuM / LynxSecure / Quest-V 的分区与 vdev 语义。

    125 GitHub starsUsed in 1 repo~3.4k tokens
    Auto-check: notes
  • Re Sdr

    dslsdzc/rev-skills

    射频逆向:信号采集、频谱分析、解调、帧同步与协议恢复、重放. An agent skill from dslsdzc/rev-skills.

    125 GitHub starsUsed in 1 repo~1.1k tokens
    Auto-check passed
  • Re Uefi

    dslsdzc/rev-skills

    UEFI/BIOS 固件:SEC/PEI/DXE/BDS 阶段判定、DXE 驱动、UEFI 模块、bootkit. An agent skill from dslsdzc/rev-skills.

    125 GitHub starsUsed in 1 repo~2.3k tokens
    Auto-check passed

Categories

Questions about Re Disk Forensics

What does Re Disk Forensics do?

磁盘/文件系统取证:删除恢复、时间线、可疑文件定位. An agent skill from dslsdzc/rev-skills. Re Disk Forensics is an agent skill from dslsdzc/rev-skills.

When should I use Re Disk Forensics?

Re Disk Forensics fits situations like: tasks that involve Digital forensics.

How do I install Re Disk Forensics in Claude Code?

Run `npx skills add dslsdzc/rev-skills --skill re-disk-forensics -a claude-code`. Or copy the skill folder (.claude/skills/re-disk-forensics in dslsdzc/rev-skills) into .claude/skills/re-disk-forensics in your project. Claude Code loads it when a task matches its description.

How do I install Re Disk Forensics in Codex?

Run `npx skills add dslsdzc/rev-skills --skill re-disk-forensics -a codex`. Or copy the skill folder (.claude/skills/re-disk-forensics in dslsdzc/rev-skills) into .agents/skills/re-disk-forensics in your project. Codex loads it when a task matches its description.

Can I use Re Disk Forensics in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add dslsdzc/rev-skills --skill re-disk-forensics -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/re-disk-forensics, .gemini/skills/re-disk-forensics, .github/skills/re-disk-forensics and .opencode/skills/re-disk-forensics in your project.

What does Re Disk Forensics need to run?

Going by SKILL.md and its folder, Re Disk Forensics needs the command-line tools its instructions call (apt, dnf, brew, winget and sqlite3). Our summary lists: Python 3.

Does Re Disk Forensics access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Re Disk Forensics safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Re Disk Forensics use?

Re Disk Forensics is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Re Disk Forensics use?

About 1.9k tokens (SKILL.md is roughly 7.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Re Disk Forensics?

Skills that share tags, products or a category with Re Disk Forensics: Ctf Crypto (ljagiello/ctf-skills, 3.4k stars), Forensics Osquery (AgentSecOps/SecOpsAgentKit, 220 stars), Performing Memory Forensics With Volatility3 Plugins (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Analyzing Memory Dumps With Volatility (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Re Disk Forensics?

dslsdzc (a GitHub user) maintains it in dslsdzc/rev-skills, which has 125 GitHub stars. The repository holds 41 skills in this directory. The repository was last updated on October 5, 2026.

Source: dslsdzc/rev-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.