Agent skill

Incident Response

by hypnguyen1209 in hypnguyen1209/offensive-claude

A skill your agent uses when responding to or forensically investigating an incident — triage acquisition (Velociraptor/KAPE), Volatility 3 memory forensics, Chainsaw/Hayabusa EVTX timelining…

MITAuto-check passedSecurity

Install Incident Response

skills CLI
$ npx skills add hypnguyen1209/offensive-claude --skill incident-response -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install hypnguyen1209/offensive-claude incident-response --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/hypnguyen1209/offensive-claude.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/incident-response .claude/skills/incident-response && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
incident-response
GitHub stars
388
Token cost
~2.5k tokens
SKILL.md length
642 words
Files
17 (incl. scripts, references)
Skills in repo
9
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when responding to or forensically investigating an incident — triage acquisition (Velociraptor/KAPE), Volatility 3 memory forensics, Chainsaw/Hayabusa EVTX timelining…

  • Forensically investigating an incident — triage acquisition (Velociraptor/KAPE)
  • SKILL.md covers When to Activate, Technique Map, Quick Start and OPSEC & Detection (summary), plus 1 more section
  • Runs Python, Shell and PowerShell scripts from its folder; calls python3 and bash
  • Volatility 3 memory forensics

What it does

Incident Response is an agent skill from hypnguyen1209/offensive-claude. Use when responding to or forensically investigating an incident — triage acquisition (Velociraptor/KAPE), Volatility 3 memory forensics, Chainsaw/Hayabusa EVTX timelining, anti-forensics detection, cloud IR, ransomware/ESXi response

Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 18 other files, including scripts and reference files (for example `references/anti-forensics-detection.md`, `references/cloud-ir.md` and `references/memory-forensics.md`).

It sits in Security, covering Digital forensics and Incident response. The repository describes itself as: Offensive security toolkit for Claude Code covering red team, exploit dev, AD attacks, EDR bypass, mobile pentest. The licence is MIT.

When your agent uses it

  • Forensically investigating an incident — triage acquisition (Velociraptor/KAPE)
  • Volatility 3 memory forensics
  • Chainsaw/Hayabusa EVTX timelining
  • Anti-forensics detection

Example prompts

  • “/incident-response”

Requirements

  • Python 3
  • A Bash shell
  • PowerShell

What it can do on your machine

Read from SKILL.md and the folder at commit a506ad3. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 9 files in scripts/ (Python, Shell and PowerShell), which the agent can run.

    Shell commands in SKILL.md call:

    • python3
    • bash

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Incident Response loads about 2.5k tokens when it runs, and up to ~16k if it reads all its reference files. Until then it costs about 63 tokens; SKILL.md has 642 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~63
When it runs · the whole SKILL.md, loaded when a task matches
~2.5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~16k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from hypnguyen1209/offensive-claude at commit a506ad3, republished under its MIT licence (© hypnguyen1209). 642 words, ~2,487 tokens.

Download SKILL.mdSave it as .claude/skills/incident-response/SKILL.md (or your agent's skills folder). This skill also uses 16 other files; get the full folder from GitHub.
name
incident-response
description
Use when responding to or forensically investigating an incident — triage acquisition (Velociraptor/KAPE), Volatility 3 memory forensics, Chainsaw/Hayabusa EVTX timelining, anti-forensics detection, cloud IR, ransomware/ESXi response
metadata.type
defensive
metadata.phase
response
metadata.tools
velociraptor, volatility3, chainsaw, hayabusa, plaso, timesketch, uac, MFTECmd, EvtxECmd, dissect, certutil, awscli, az, gcloud
metadata.mitre
TA0005
kill_chain.phase
report
kill_chain.step
8
kill_chain.attck_tactics
TA0005, TA0007, TA0040, TA0010
kill_chain.attck_techniques
T1070, T1070.001, T1070.004, T1070.006, T1562.001, T1070.008, T1055, T1014, T1003.001, T1486, T1490, T1485, T1078.004, T1552.005, T1528, T1219
depends_on
red-team-ops, threat-hunting
feeds_into
threat-hunting, malware-analysis

Incident Response & Digital Forensics

When to Activate

  • Active security incident: triage, scoping, evidence acquisition, containment, eradication
  • Memory forensics — process injection, rootkit (incl. eBPF), credential-theft, network artifacts
  • Windows event-log / artifact timelining and super-timeline reconstruction
  • Anti-forensics detection — timestomping, log clearing, secure deletion, VSS recovery
  • Cloud incident response — AWS/Azure/GCP identity-plane attacks and forensic collection
  • Ransomware / extortion response — hypervisor (ESXi) encryption, backup destruction, fast-dwell intrusions
  • Verifying suspect DFIR tooling used as adversary persistence (Velociraptor CVE-2025-6264)
  • Repository-compromise post-mortem — a poisoned public repo / force-pushed malicious commit / deleted PR (recover via dangling commits + GH Archive + Wayback + Events API; see references/repo-compromise-forensics.md)

Technique Map

TechniqueATT&CKCWEReferenceScript
Order-of-volatility live triage (Velociraptor/KAPE/UAC/CatScale)T1074CWE-778references/triage-collection.mdscripts/triage_collector.py
Offline collector build + RAM acquisition (winpmem/LiME/AVML)T1074CWE-778references/triage-collection.mdscripts/triage_collector.py
Suspect-tooling verification (Velociraptor CVE-2025-6264)T1219CWE-269references/triage-collection.mdscripts/triage_collector.py
Volatility 3 process/injection analysis (malfind, hollow)T1055CWE-noinforeferences/memory-forensics.mdscripts/vol3_triage.py
Credential extraction from memory (LSASS, hives)T1003.001CWE-522references/memory-forensics.mdscripts/vol3_triage.py
Kernel + eBPF rootkit detection (LinkPro, linux.ebpf)T1014CWE-269references/memory-forensics.mdscripts/ebpf_rootkit_hunt.sh
EVTX Sigma hunting & fast timeline (Chainsaw/Hayabusa)T1070.001CWE-778references/windows-evtx-timeline.mdscripts/evtx_hunt.sh
Super-timeline (plaso) + Timesketch correlationT1070CWE-778references/windows-evtx-timeline.mdscripts/evtx_hunt.sh
Timestomping detection ($SI vs $FN, USN FILE_CREATE)T1070.006CWE-noinforeferences/anti-forensics-detection.mdscripts/timestomp_detect.py
Log/journal clearing & VSS recoveryT1070.001, T1490CWE-778references/anti-forensics-detection.mdscripts/timestomp_detect.py
Cloud IR — IMDSv2/SSRF cred theft, CloudTrail/GuardDutyT1552.005, T1078.004CWE-918references/cloud-ir.mdscripts/cloud_ir_collect.py
Entra ID / token theft, identity-plane containmentT1528, T1078.004CWE-287references/cloud-ir.mdscripts/cloud_ir_collect.py
Ransomware rapid triage (Windows/Linux)T1486, T1490, T1485CWE-noinforeferences/ransomware-esxi-ir.mdscripts/ransomware_triage.ps1
ESXi / hypervisor ransomware response (UNC3944)T1486CWE-noinforeferences/ransomware-esxi-ir.mdscripts/ransomware_triage.ps1

Quick Start

bash
# 0. PRESERVE ORDER OF VOLATILITY — RAM before disk, never reboot a live host first.
#    Windows RAM:  winpmem_mini_x64.exe mem.raw        Linux RAM: AVML  ./avml mem.lime
# 1. Network-wide / endpoint triage (pick one):
python3 scripts/triage_collector.py --os auto --out /evidence --velociraptor-collector
#    Verify any Velociraptor already on-host is NOT adversary persistence (CVE-2025-6264):
python3 scripts/triage_collector.py --check-velociraptor   # flags <0.73.5 / unknown service

# 2. Memory forensics (Windows or Linux dump):
python3 scripts/vol3_triage.py -f /evidence/mem.raw --os windows --hunt-injection --dump-suspect
bash   scripts/ebpf_rootkit_hunt.sh   # Linux live/IR eBPF rootkit hunt (LinkPro-aware)

# 3. Windows event-log fast timeline + Sigma hunt:
bash scripts/evtx_hunt.sh -d /evidence/C/Windows/System32/winevt/Logs -o /evidence/timeline

# 4. Anti-forensics: timestomp / USN tamper detection from $MFT + $J:
python3 scripts/timestomp_detect.py --mft /evidence/mft.csv --usn /evidence/usn.csv

# 5. Cloud breach (identity-plane first):
python3 scripts/cloud_ir_collect.py aws --collect-cloudtrail --contain-key AKIA... --enforce-imdsv2

# 6. Ransomware on a Windows host (rapid scope, do BEFORE eradication):
powershell -ep bypass -File scripts/ransomware_triage.ps1 -OutDir C:\IR

OPSEC & Detection (summary)

IR is defensive; "OPSEC" below = handling rules that keep evidence admissible and avoid tipping off an adversary who may be monitoring (UNC3944 joins IR bridges in real time).

TechniqueTelemetry / IOCDetection (Sigma / EDR)OPSEC / evidence note
Live triageNew service/scheduled task for collector; large file writes to evidence pathBaseline expected DFIR tooling; alert on unsigned collectorsCollect RAM first; never write evidence to the suspect volume; hash everything
Velociraptor abusevelociraptor.exe svc <0.73.5; MSI from Azure Blob; relaunch after isolationSigma: unexpected Velociraptor service install; CVE-2025-6264 UpdateConfigTreat unexpected Velociraptor as persistence, not your tooling
Memory injectionRX/RWX private VAD not file-backed (malfind); reparented svchostVol3 malfind/hollowprocesses; EDR unbacked-execDocument plugin+offset provenance; keep raw dump read-only
eBPF rootkitbpf_override_return; getdents/sys_bpf hooks; XDP magic-packet (win=54321); /etc/ld.so.preloadlinux.ebpf vs baseline; ss(netlink) vs /proc/net diff; YARA MAL_LinkPro_*bpftool/ps/ss lie on host — acquire RAM out-of-band (hypervisor/LiME RO)
EVTX clearing1102 (Security cleared), 104 (System cleared), gaps in EventRecordIDChainsaw/Hayabusa Sigma; alert on 1102/104Pull EVTX from VSS/disk image, not the tampered live log
Timestomp$SI ≠ $FN create time; sub-second zeros; USN FILE_CREATE mismatchtimestomp_detect.py; MFTECmd Created0x10 vs Created0x30$FN is harder to forge — anchor truth to it + USN/$LogFile
Cloud cred theftInstanceCredentialExfiltration.OutsideAWS; impossible-travel sign-in; CloudTrail StopLoggingGuardDuty findings; Sentinel KQL risky sign-insSnapshot+immutable-export BEFORE remediation; logs to a SIEM the attacker can't reach
Ransomware/ESXiMass file rename/ext change; vCenter/ESXi SSH on; bulk vim-cmd VM power-offSIEM: high-volume VM power-off from one host; vpxuser anomaliesImage before decrypt attempts; preserve note + sample; assume comms compromised
Show full SKILL.md (150 more words)Show less

Deep Dives

  • references/triage-collection.md — Order of volatility, RAM acquisition (winpmem/AVML/LiME), Velociraptor 0.75 offline collectors & hunts, KAPE targets, UAC/CatScale for Unix/ESXi, suspect-tooling verification incl. Velociraptor CVE-2025-6264.
  • references/memory-forensics.md — Volatility 3 symbol-table workflow, Windows injection/credential/rootkit plugins, Linux pslist/check_syscall/hidden_modules, eBPF rootkit detection (LinkPro, linux.ebpf, bpf_override_return), dump extraction.
  • references/windows-evtx-timeline.md — Chainsaw v2 & Hayabusa v3 Sigma hunting, key Event IDs, EvtxECmd/Eric Zimmerman parsers, plaso super-timeline, Timesketch + Dissect/Acquire enterprise scaling.
  • references/anti-forensics-detection.md — Timestomping ($SI/$FN + USN cross-validation), log/journal clearing (1102/104, $LogFile gaps), secure-deletion artifacts, VSS recovery, $MFT/$J/$LogFile QuadLink correlation.
  • references/cloud-ir.md — NIST SP 800-61r3 / SP 800-201, AWS CloudTrail/GuardDuty/IMDSv2-SSRF, Azure Entra ID token theft & KQL, GCP audit logs, identity-plane containment, automated evidence preservation.
  • references/ransomware-esxi-ir.md — Ransomware rapid triage & decision flow, Scattered Spider/UNC3944 ESXi LotL chain, backup destruction, cross-platform builders (LockBit 5.0/DragonForce), containment & negotiation hygiene.
  • references/repo-compromise-forensics.md — poisoned public-repo post-mortem from four INDEPENDENT, attacker-uncontrollable sources: dangling/force-pushed commits (dangling_commit_finder.py, git fsck via git_safe), GH Archive + Wayback CDX + live Events API (gharchive_recover.py); hypothesis→verify-at-source (evidence_kit)→adversarial-check→report, attribution-with-confidence, BigQuery kept optional.

© hypnguyen1209, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 16 other files (scripts, references) in skills/incident-response of hypnguyen1209/offensive-claude.

  • SKILL.md
  • references/anti-forensics-detection.md
  • references/cloud-ir.md
  • references/memory-forensics.md
  • references/ransomware-esxi-ir.md
  • references/repo-compromise-forensics.md
  • references/triage-collection.md
  • references/windows-evtx-timeline.md
  • scripts/cloud_ir_collect.py
  • scripts/dangling_commit_finder.py
  • scripts/ebpf_rootkit_hunt.sh
  • scripts/evtx_hunt.sh
  • scripts/gharchive_recover.py
  • scripts/ransomware_triage.ps1
  • scripts/timestomp_detect.py
  • scripts/triage_collector.py
  • scripts/vol3_triage.py

Open the folder on GitHubat commit a506ad3

Compare with similar skills

Incident Response next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Incident Response compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Incident Response this skillhypnguyen1209/offensive-claude388—~2.5kAutomated safety check: PassMIT
Forensics OsqueryAgentSecOps/SecOpsAgentKit2201 repos~4.9kAutomated safety check: NotesCustom licence
Ir VelociraptorAgentSecOps/SecOpsAgentKit2201 repos~3.1kAutomated safety check: PassCustom licence
Analyzing Memory Forensics With Lime And Volatilitymukul975/Anthropic-Cybersecurity-Skills34k—~631Automated safety check: PassApache-2.0
Analyzing Outlook Pst For Email Forensicsmukul975/Anthropic-Cybersecurity-Skills34k—~3.2kAutomated safety check: PassApache-2.0
Extracting Memory Artifacts With Rekallmukul975/Anthropic-Cybersecurity-Skills34k—~642Automated safety check: PassApache-2.0

Similar skills

  • Forensics Osquery

    AgentSecOps/SecOpsAgentKit

    SQL-powered forensic investigation and system interrogation using osquery to query operating systems as relational databases.

    220 GitHub starsUsed in 1 repo~4.9k tokens
    SecurityAuto-check: notes
  • Ir Velociraptor

    AgentSecOps/SecOpsAgentKit

    Endpoint visibility, digital forensics, and incident response using Velociraptor Query Language (VQL) for evidence collection and threat hunting at scale.

    220 GitHub starsUsed in 1 repo~3.1k tokens
    SecurityAuto-check passed
  • Analyzing Memory Forensics With Lime And Volatility

    mukul975/Anthropic-Cybersecurity-Skills

    Performs Linux memory acquisition using LiME (Linux Memory Extractor) kernel module and analysis with Volatility 3 framework.

    34k GitHub stars~631 tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Analyzing Outlook Pst For Email Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Parse Microsoft Outlook PST and OST files using libpff and pst-utils to extract message content, headers, attachments, deleted items, and MAPI metadata, including recovery of items from the…

    34k GitHub stars~3.2k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Extracting Memory Artifacts With Rekall

    mukul975/Anthropic-Cybersecurity-Skills

    Uses Rekall memory forensics framework to analyze memory dumps for process hollowing, injected code via VAD anomalies, hidden processes, and rootkit detection.

    34k GitHub stars~642 tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Performing Memory Forensics With Volatility3

    mukul975/Anthropic-Cybersecurity-Skills

    Analyze volatile memory (RAM) dumps using the Volatility 3 framework to extract running processes, network connections, loaded modules, credentials, and encryption keys, and to detect process…

    34k GitHub stars~3k tokensUpdated 1 mo ago
    SecurityAuto-check: notes

More from hypnguyen1209/offensive-claude

All 9 skills in this repo
  • Crypto Analysis

    hypnguyen1209/offensive-claude

    A skill your agent uses when assessing cryptography — TLS/PKI auditing, RSA/ECC key attacks, ECDSA nonce lattice recovery, symmetric/AEAD misuse, JWT/JOSE forgery, hash cracking, post-quantum…

    388 GitHub stars~2.2k tokensUpdated 13 days ago
    Auto-check passed
  • Malware Analysis

    hypnguyen1209/offensive-claude

    A skill your agent uses when reverse-engineering or detecting malware — static triage + capa/YARA-X, emulation/DBI/.NET unpacking, dynamic/fileless/Volatility 3 memory analysis, C2 config extraction…

    388 GitHub stars~2.3k tokensUpdated 13 days ago
    Auto-check passed
  • Recon Osint

    hypnguyen1209/offensive-claude

    A skill your agent uses when mapping a target's external attack surface or gathering OSINT — subdomain enumeration, attack-surface mapping (httpx/katana/JS secrets), subdomain takeover…

    388 GitHub stars~2.2k tokensUpdated 13 days ago
    Auto-check passed
  • Threat Hunting

    hypnguyen1209/offensive-claude

    A skill your agent uses when hunting threats or engineering detections — ATT&CK Detection-Strategies, Sigma + correlation with Detection-as-Code CI, Windows endpoint hunting…

    388 GitHub stars~2.4k tokensUpdated 13 days ago
    Auto-check passed
  • Threat Model Discipline

    hypnguyen1209/offensive-claude

    A skill your agent uses when starting an engagement, before exploitation, or whenever the attack surface changes — build/validate the threat model and detect drift (new unreviewed surface) before…

    388 GitHub stars~660 tokensUpdated 13 days ago
    Auto-check passed
  • Writing Offensive Skills

    hypnguyen1209/offensive-claude

    A skill your agent uses when creating or editing a skill in this offensive-claude repo — for the SKILL.md conventions (trigger descriptions, technique map, runnable scripts, OPSEC/detection…

    388 GitHub stars~826 tokensUpdated 13 days ago
    Auto-check passed

Questions about Incident Response

What does Incident Response do?

A skill your agent uses when responding to or forensically investigating an incident — triage acquisition (Velociraptor/KAPE), Volatility 3 memory forensics, Chainsaw/Hayabusa EVTX timelining…. Incident Response is an agent skill from hypnguyen1209/offensive-claude.

When should I use Incident Response?

Incident Response fits situations like: forensically investigating an incident — triage acquisition (Velociraptor/KAPE); volatility 3 memory forensics; chainsaw/Hayabusa EVTX timelining; anti-forensics detection.

How do I install Incident Response in Claude Code?

Run `npx skills add hypnguyen1209/offensive-claude --skill incident-response -a claude-code`. Or copy the skill folder (skills/incident-response in hypnguyen1209/offensive-claude) into .claude/skills/incident-response in your project. Claude Code loads it when a task matches its description.

How do I install Incident Response in Codex?

Run `npx skills add hypnguyen1209/offensive-claude --skill incident-response -a codex`. Or copy the skill folder (skills/incident-response in hypnguyen1209/offensive-claude) into .agents/skills/incident-response in your project. Codex loads it when a task matches its description.

Can I use Incident Response in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add hypnguyen1209/offensive-claude --skill incident-response -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/incident-response, .gemini/skills/incident-response, .github/skills/incident-response and .opencode/skills/incident-response in your project.

What does Incident Response need to run?

Going by SKILL.md and its folder, Incident Response needs Python, a shell and PowerShell for the scripts in its folder and the command-line tools its instructions call (python3 and bash). Our summary lists: Python 3; A Bash shell; PowerShell.

Does Incident Response access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Incident Response safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Incident Response use?

Incident Response is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Incident Response use?

About 2.5k tokens (SKILL.md is roughly 9.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 13k tokens, read only when the agent opens those files.

What are the alternatives to Incident Response?

Skills that share tags, products or a category with Incident Response: Forensics Osquery (AgentSecOps/SecOpsAgentKit, 220 stars), Ir Velociraptor (AgentSecOps/SecOpsAgentKit, 220 stars), Analyzing Memory Forensics With Lime And Volatility (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Analyzing Outlook Pst For Email Forensics (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Incident Response?

hypnguyen1209 (a GitHub user) maintains it in hypnguyen1209/offensive-claude, which has 388 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on September 28, 2026.

Source: hypnguyen1209/offensive-claude on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.