Forensics Osquery
AgentSecOps/SecOpsAgentKit
SQL-powered forensic investigation and system interrogation using osquery to query operating systems as relational databases.
Captures an analyzable sample from a live system when the target leaves no file on disk, by finding abnormal executable memory and the execution context that reached it.
SKILL.md written in Chinese; this summary is our English description.
$ npx skills add dslsdzc/rev-skills --skill re-sample-acquire -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install dslsdzc/rev-skills re-sample-acquire --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/re-sample-acquire .claude/skills/re-sample-acquire && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "re-sample-acquire" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-sample-acquire into .claude/skills/re-sample-acquire/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-sample-acquire", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-sample-acquireType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add dslsdzc/rev-skills --skill re-sample-acquire -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install dslsdzc/rev-skills re-sample-acquire --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/re-sample-acquire .agents/skills/re-sample-acquire && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "re-sample-acquire" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-sample-acquire into .agents/skills/re-sample-acquire/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-sample-acquire", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add dslsdzc/rev-skills --skill re-sample-acquire -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install dslsdzc/rev-skills re-sample-acquire --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/re-sample-acquire .cursor/skills/re-sample-acquire && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "re-sample-acquire" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-sample-acquire into .cursor/skills/re-sample-acquire/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-sample-acquire", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/dslsdzc/rev-skills.git --path .claude/skills/re-sample-acquire--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add dslsdzc/rev-skills --skill re-sample-acquire -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install dslsdzc/rev-skills re-sample-acquire --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/re-sample-acquire .gemini/skills/re-sample-acquire && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "re-sample-acquire" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-sample-acquire into .gemini/skills/re-sample-acquire/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-sample-acquire", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install dslsdzc/rev-skills re-sample-acquireInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add dslsdzc/rev-skills --skill re-sample-acquire -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/re-sample-acquire .github/skills/re-sample-acquire && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "re-sample-acquire" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-sample-acquire into .github/skills/re-sample-acquire/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-sample-acquire", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add dslsdzc/rev-skills --skill re-sample-acquire -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install dslsdzc/rev-skills re-sample-acquire --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/dslsdzc/rev-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/re-sample-acquire .opencode/skills/re-sample-acquire && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "re-sample-acquire" agent skill from https://github.com/dslsdzc/rev-skills/tree/main/.claude/skills/re-sample-acquire into .opencode/skills/re-sample-acquire/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "re-sample-acquire", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
re-sample-acquireCaptures an analyzable sample from a live system when the target leaves no file on disk, by finding abnormal executable memory and the execution context that reached it.
The SKILL.md is in Chinese. Its core rule is not to guess process names but to look for abnormal executable memory and the context that reached it, detecting from the final memory artifact rather than the injection method, and to ask first who created the memory, by what path and who holds the mapping rights. A task classifier routes cases: only a described symptom, a known process with no file on disk, server-side resident payloads, suspected kernel-mode code, embedded or seL4 targets, and callbacks or downloads where a raw sample is wanted.
Four platform branches have different observation models: Windows regions, threads and module chains with Sysmon and ETW; Linux memory maps with tracepoints and BPF LSM; macOS Mach tasks with Endpoint Security; and seL4 capability provenance. The skill is not for cases where a sample file exists, for offline memory image forensics or for dumping a known PID. It sets an authorization red line: collect only from your own or written-authorized systems, since acquisition leaves visible traces. It acquires only and does not hide from detection.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit bd21db8. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Runtime Memory Sample Acquisition loads about 2k tokens when it runs, and up to ~8k if it reads all its reference files. Until then it costs about 94 tokens; SKILL.md has 475 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from dslsdzc/rev-skills at commit bd21db8, republished under its Apache-2.0 licence (© dslsdzc). 475 words, ~2,019 tokens.
.claude/skills/re-sample-acquire/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.<CORE RULE>
**不猜进程名、不以「找到进程」为第一目标**——找「异常执行内存」+「到达这块内存的执行上下文」。
检测基于**最终的内存 artifact**,不依赖"样本用了哪个注入 API"(未知注入方法也可能被 artifact 检出;hook 到某个 API 不等于覆盖了全部注入方式)。
**先问 provenance:这块可执行内存是谁创建的、通过什么路径进来的、谁持有映射权限**——再谈它属于哪个进程。
</CORE RULE>
| 用户目的 | 路径 |
|---|---|
| 只有现象描述("某程序不落盘""行为异常"),没有样本文件 | → 步骤 1(异常执行区扫描)→ 2(执行上下文归属)→ 4(dump 整区) |
| 已知进程,但磁盘上没有样本文件(注入/内存驻留) | → 步骤 2 → 4 |
| 服务端常驻载荷(Web 中间件/Java 等,请求触发) | → 平台分支的"服务端"节(内存马) |
| 载荷疑似驱动/内核态(读写内存类外挂/rootkit) | → [[platform-windows]] 内核侧 |
| 嵌入式/微内核目标(seL4 系统) | → [[platform-sel4]](capability provenance 路线) |
| 有回连/下载行为,想拿原始样本 | → 步骤 7(网络与落盘侧) |
现场采集
├─ 已有样本文件(磁盘上有)→ 不需要本技能,直接 [[re-triage]] 初勘
├─ Windows 目标 → [[platform-windows]](VAD/region + 线程 + 模块链 + ETW/Sysmon)
├─ Linux 目标 → [[platform-linux]](VMA + mmap/mprotect 追踪 + process_vm_readv)
├─ macOS 目标 → [[platform-macos]](Mach task VM + Endpoint Security)
├─ seL4 目标 → [[platform-sel4]](capability/VSpace 审计,不是"扫描进程")
└─ 不知平台/跨平台 → 先按步骤 1 的平台无关判据走,再进对应分支平台观测模型不同,方法不能机械翻译(下表是各分支的分工,不是同义替换):
| 平台 | 观测对象 | 事件源(trigger) | 读取(ground truth) | 权限模型 |
|---|---|---|---|---|
| Windows | 进程 VAD/region + 线程 + 模块链 | Sysmon 8/10/25、ETW(含 Threat-Intelligence)、内核回调 | VirtualQueryEx / ReadProcessMemory / PE-sieve | 管理员 + 调试权限 |
| Linux | 进程 VMA(/proc/<pid>/maps) | tracepoint/kprobe、BPF LSM(file_mprotect 等 hook) | process_vm_readv() / ptrace / gcore | ptrace access check(含 Yama) |
| macOS | Mach task + VM region | Endpoint Security(MMAP/MPROTECT/REMOTE_THREAD_CREATE/GET_TASK) | mach_vm_read / mach_vm_read_overwrite(需 task port) | SIP / Hardened Runtime / task port 授权 |
| seL4 | capability(VSpace / frame / TCB) | fault endpoint + 系统构造期记录 | 无 capability 即无访问权 | capability 制(不存在"root 全读"模型) |
RE_AUTH = owned / research)。采集动作本身(枚举、hook、读内存、dump、加载监控组件)痕迹明显,会触发反作弊 / EDR / 业务监控;生产环境或他人设备上执行属越权,先确认授权与停止条件hasherezade/pe-sieve、hasherezade/hollows_hunter),核对 release 页 sha256;验证 pe-sieve.exe /helpprocdump -ma <pid> out.dmp;验证 procdump -?/proc 解析(python3,[[re-python]])、gdb/gcore([[re-memdump]])、bpftrace/perf/BPF LSM([[re-ebpf]])、fridacat /proc/<pid>/maps | head 能看到 VMA 的地址/权限/backing pathnamelldb / vmmap / otool([[re-lldb]]、[[re-format-macho]]);Mach VM API(mach_vm_region* / mach_vm_read*,需 task port);Endpoint Security 客户端(需 entitlement 与用户授权)各步的平台对应实现见对应平台分支;此处只列做什么与判据。
VirtualQueryEx/NtQueryVirtualMemory);Linux = VMA(/proc/<pid>/maps,6.11+ 可用 PROCMAP_QUERY ioctl 高效过滤);macOS = VM region(vm_region_recurse_64/mach_vm_region*);seL4 = VSpace 映射审计(见分支)MEM_IMAGE + module stomping/DLL hollowing、COW 页仍报 MEM_IMAGE;Linux 文件背书映射被改写;macOS 文件背书 region 被 patch)VirtualQueryEx+NtQueryVirtualMemory 取映射路径与 PEB 模块链比对("有映射无模块条目"= 被摘链隐藏);Linux 用 maps 的 pathname/inode 与 ELF 磁盘副本比对;macOS 用 dyld 记录与 VM region 比对NtQueryInformationThread + ThreadQuerySetWin32StartAddress;macOS thread backtrace)→ 归属到执行区;Linux 用 /proc/<pid>/task/ 枚举线程,stat 的 wchan/state 作辅助线索,PC 与返回地址靠栈回溯(eu-stack/gdb)取/proc/<pid>/maps、PROCMAP_QUERY)、mmap/mprotect 追踪(tracepoint/kprobe/BPF LSM)、process_vm_readv 与 ptrace dump、ELF 内存-磁盘 diff、memfd 与 deleted 映射、JIT 误报mach_vm_read、Endpoint Security(MMAP/MPROTECT/REMOTE_THREAD_CREATE/GET_TASK)、Mach-O/dyld provenance、task port 与 SIP/Hardened Runtime 边界MEM_IMAGE+COW,Linux/macOS 文件背书映射被改写)SetThreadContext、借模块内跳转指令等会绕过——PC 与调用栈一起看© dslsdzc, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 4 other files (references) in .claude/skills/re-sample-acquire of dslsdzc/rev-skills.
Open the folder on GitHubat commit bd21db8
Runtime Memory Sample Acquisition next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Runtime Memory Sample Acquisition this skilldslsdzc/rev-skills | 117 | — | ~2k | Automated safety check: Pass | Apache-2.0 | |
| Forensics OsqueryAgentSecOps/SecOpsAgentKit | 219 | 1 repos | ~4.9k | Automated safety check: Notes | Custom licence | |
| Performing Memory Forensics With Volatility3 Pluginsmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~2.1k | Automated safety check: Pass | Apache-2.0 | |
| Analyzing Memory Dumps With Volatilitymukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | |
| Memory Forensics Volatilityyaklang/hack-skills | 2.4k | — | ~2.5k | Automated safety check: Pass | MIT | |
| Game Automationrehan-remade/universal-modder | 4.7k | — | ~1.9k | Automated safety check: Pass | MIT |
AgentSecOps/SecOpsAgentKit
SQL-powered forensic investigation and system interrogation using osquery to query operating systems as relational databases.
mukul975/Anthropic-Cybersecurity-Skills
Analyze memory dumps using Volatility3 plugins to detect injected code, rootkits, credential theft, and malware artifacts in Windows, Linux, and macOS memory images.
mukul975/Anthropic-Cybersecurity-Skills
Analyzes RAM memory dumps from compromised systems using the Volatility framework to identify malicious processes, injected code, network connections, loaded modules, and extracted credentials.
yaklang/hack-skills
Memory forensics playbook using Volatility 2/3. An agent skill from yaklang/hack-skills.
rehan-remade/universal-modder
Launch, see and drive a real game so an agent can test its own mods.
ljagiello/ctf-skills
Provides malware analysis and network traffic techniques for CTF challenges.
dslsdzc/rev-skills
威胁归因方法论:钻石模型、基础设施图谱、置信度分级与归因报告. An agent skill from dslsdzc/rev-skills.
dslsdzc/rev-skills
函数式语言运行时逆向(Haskell/OCaml):闭包/堆对象模型、调用约定、数据流优先策略. An agent skill from dslsdzc/rev-skills.
dslsdzc/rev-skills
虚拟化逆向:VT-x/SVM、hypervisor 检测、VMCS/EPT 分析, 以及 Xen / QNX Hypervisor / Jailhouse / ACRN / Bao / Hyper-V·VMBus / XtratuM / LynxSecure / Quest-V 的分区与 vdev 语义。
dslsdzc/rev-skills
射频逆向:信号采集、频谱分析、解调、帧同步与协议恢复、重放. An agent skill from dslsdzc/rev-skills.
dslsdzc/rev-skills
UEFI/BIOS 固件:SEC/PEI/DXE/BDS 阶段判定、DXE 驱动、UEFI 模块、bootkit. An agent skill from dslsdzc/rev-skills.
dslsdzc/rev-skills
现代 C++ 二进制逆向:RTTI/异常/虚表恢复、ABI 识别、mangling 解码. An agent skill from dslsdzc/rev-skills.
Categories
Captures an analyzable sample from a live system when the target leaves no file on disk, by finding abnormal executable memory and the execution context that reached it. md is in Chinese. Its core rule is not to guess process names but to look for abnormal executable memory and the context that reached it, detecting from the final memory artifact rather than the injection method, and to ask first who created the memory, by what path and who holds the mapping rights.
Runtime Memory Sample Acquisition fits situations like: analyzing fileless or memory-resident code that never touches disk; turning a described symptom into a dumpable sample on a system you own; investigating injected code in a known process with no file on disk; choosing an acquisition method for Windows, Linux, macOS or seL4.
Run `npx skills add dslsdzc/rev-skills --skill re-sample-acquire -a claude-code`. Or copy the skill folder (.claude/skills/re-sample-acquire in dslsdzc/rev-skills) into .claude/skills/re-sample-acquire in your project. Claude Code loads it when a task matches its description.
Run `npx skills add dslsdzc/rev-skills --skill re-sample-acquire -a codex`. Or copy the skill folder (.claude/skills/re-sample-acquire in dslsdzc/rev-skills) into .agents/skills/re-sample-acquire in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add dslsdzc/rev-skills --skill re-sample-acquire -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/re-sample-acquire, .gemini/skills/re-sample-acquire, .github/skills/re-sample-acquire and .opencode/skills/re-sample-acquire in your project.
SKILL.md names no scripts, command-line tools or credentials: Runtime Memory Sample Acquisition is instructions for the agent only. Our summary lists: Written authorization for the target system; Administrator or debug privileges on the target; Platform tools such as PE-sieve on Windows.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Runtime Memory Sample Acquisition is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2k tokens (SKILL.md is roughly 8.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 6k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Runtime Memory Sample Acquisition: Forensics Osquery (AgentSecOps/SecOpsAgentKit, 219 stars), Performing Memory Forensics With Volatility3 Plugins (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Analyzing Memory Dumps With Volatility (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Memory Forensics Volatility (yaklang/hack-skills, 2.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
dslsdzc (a GitHub user) maintains it in dslsdzc/rev-skills, which has 117 GitHub stars. The repository holds 41 skills in this directory. The repository was last updated on October 5, 2026.
Source: dslsdzc/rev-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.