Forensics Osquery
AgentSecOps/SecOpsAgentKit
SQL-powered forensic investigation and system interrogation using osquery to query operating systems as relational databases.
A skill your agent uses when responding to or forensically investigating an incident — triage acquisition (Velociraptor/KAPE), Volatility 3 memory forensics, Chainsaw/Hayabusa EVTX timelining…
$ npx skills add hypnguyen1209/offensive-claude --skill incident-response -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install hypnguyen1209/offensive-claude incident-response --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/hypnguyen1209/offensive-claude.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/incident-response .claude/skills/incident-response && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "incident-response" agent skill from https://github.com/hypnguyen1209/offensive-claude/tree/main/skills/incident-response into .claude/skills/incident-response/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "incident-response", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/hypnguyen1209/offensive-claude/tree/main/skills/incident-responseType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add hypnguyen1209/offensive-claude --skill incident-response -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install hypnguyen1209/offensive-claude incident-response --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/hypnguyen1209/offensive-claude.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/incident-response .agents/skills/incident-response && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "incident-response" agent skill from https://github.com/hypnguyen1209/offensive-claude/tree/main/skills/incident-response into .agents/skills/incident-response/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "incident-response", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add hypnguyen1209/offensive-claude --skill incident-response -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install hypnguyen1209/offensive-claude incident-response --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/hypnguyen1209/offensive-claude.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/incident-response .cursor/skills/incident-response && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "incident-response" agent skill from https://github.com/hypnguyen1209/offensive-claude/tree/main/skills/incident-response into .cursor/skills/incident-response/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "incident-response", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/hypnguyen1209/offensive-claude.git --path skills/incident-response--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add hypnguyen1209/offensive-claude --skill incident-response -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install hypnguyen1209/offensive-claude incident-response --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/hypnguyen1209/offensive-claude.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/incident-response .gemini/skills/incident-response && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "incident-response" agent skill from https://github.com/hypnguyen1209/offensive-claude/tree/main/skills/incident-response into .gemini/skills/incident-response/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "incident-response", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install hypnguyen1209/offensive-claude incident-responseInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add hypnguyen1209/offensive-claude --skill incident-response -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/hypnguyen1209/offensive-claude.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/incident-response .github/skills/incident-response && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "incident-response" agent skill from https://github.com/hypnguyen1209/offensive-claude/tree/main/skills/incident-response into .github/skills/incident-response/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "incident-response", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add hypnguyen1209/offensive-claude --skill incident-response -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install hypnguyen1209/offensive-claude incident-response --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/hypnguyen1209/offensive-claude.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/incident-response .opencode/skills/incident-response && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "incident-response" agent skill from https://github.com/hypnguyen1209/offensive-claude/tree/main/skills/incident-response into .opencode/skills/incident-response/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "incident-response", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
incident-responseA skill your agent uses when responding to or forensically investigating an incident — triage acquisition (Velociraptor/KAPE), Volatility 3 memory forensics, Chainsaw/Hayabusa EVTX timelining…
Incident Response is an agent skill from hypnguyen1209/offensive-claude. Use when responding to or forensically investigating an incident — triage acquisition (Velociraptor/KAPE), Volatility 3 memory forensics, Chainsaw/Hayabusa EVTX timelining, anti-forensics detection, cloud IR, ransomware/ESXi response
Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 18 other files, including scripts and reference files (for example `references/anti-forensics-detection.md`, `references/cloud-ir.md` and `references/memory-forensics.md`).
It sits in Security, covering Digital forensics and Incident response. The repository describes itself as: Offensive security toolkit for Claude Code covering red team, exploit dev, AD attacks, EDR bypass, mobile pentest. The licence is MIT.
Read from SKILL.md and the folder at commit a506ad3. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 9 files in scripts/ (Python, Shell and PowerShell), which the agent can run.
Shell commands in SKILL.md call:
python3bashFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Incident Response loads about 2.5k tokens when it runs, and up to ~16k if it reads all its reference files. Until then it costs about 63 tokens; SKILL.md has 642 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from hypnguyen1209/offensive-claude at commit a506ad3, republished under its MIT licence (© hypnguyen1209). 642 words, ~2,487 tokens.
.claude/skills/incident-response/SKILL.md (or your agent's skills folder). This skill also uses 16 other files; get the full folder from GitHub.references/repo-compromise-forensics.md)| Technique | ATT&CK | CWE | Reference | Script |
|---|---|---|---|---|
| Order-of-volatility live triage (Velociraptor/KAPE/UAC/CatScale) | T1074 | CWE-778 | references/triage-collection.md | scripts/triage_collector.py |
| Offline collector build + RAM acquisition (winpmem/LiME/AVML) | T1074 | CWE-778 | references/triage-collection.md | scripts/triage_collector.py |
| Suspect-tooling verification (Velociraptor CVE-2025-6264) | T1219 | CWE-269 | references/triage-collection.md | scripts/triage_collector.py |
| Volatility 3 process/injection analysis (malfind, hollow) | T1055 | CWE-noinfo | references/memory-forensics.md | scripts/vol3_triage.py |
| Credential extraction from memory (LSASS, hives) | T1003.001 | CWE-522 | references/memory-forensics.md | scripts/vol3_triage.py |
| Kernel + eBPF rootkit detection (LinkPro, linux.ebpf) | T1014 | CWE-269 | references/memory-forensics.md | scripts/ebpf_rootkit_hunt.sh |
| EVTX Sigma hunting & fast timeline (Chainsaw/Hayabusa) | T1070.001 | CWE-778 | references/windows-evtx-timeline.md | scripts/evtx_hunt.sh |
| Super-timeline (plaso) + Timesketch correlation | T1070 | CWE-778 | references/windows-evtx-timeline.md | scripts/evtx_hunt.sh |
| Timestomping detection ($SI vs $FN, USN FILE_CREATE) | T1070.006 | CWE-noinfo | references/anti-forensics-detection.md | scripts/timestomp_detect.py |
| Log/journal clearing & VSS recovery | T1070.001, T1490 | CWE-778 | references/anti-forensics-detection.md | scripts/timestomp_detect.py |
| Cloud IR — IMDSv2/SSRF cred theft, CloudTrail/GuardDuty | T1552.005, T1078.004 | CWE-918 | references/cloud-ir.md | scripts/cloud_ir_collect.py |
| Entra ID / token theft, identity-plane containment | T1528, T1078.004 | CWE-287 | references/cloud-ir.md | scripts/cloud_ir_collect.py |
| Ransomware rapid triage (Windows/Linux) | T1486, T1490, T1485 | CWE-noinfo | references/ransomware-esxi-ir.md | scripts/ransomware_triage.ps1 |
| ESXi / hypervisor ransomware response (UNC3944) | T1486 | CWE-noinfo | references/ransomware-esxi-ir.md | scripts/ransomware_triage.ps1 |
# 0. PRESERVE ORDER OF VOLATILITY — RAM before disk, never reboot a live host first.
# Windows RAM: winpmem_mini_x64.exe mem.raw Linux RAM: AVML ./avml mem.lime
# 1. Network-wide / endpoint triage (pick one):
python3 scripts/triage_collector.py --os auto --out /evidence --velociraptor-collector
# Verify any Velociraptor already on-host is NOT adversary persistence (CVE-2025-6264):
python3 scripts/triage_collector.py --check-velociraptor # flags <0.73.5 / unknown service
# 2. Memory forensics (Windows or Linux dump):
python3 scripts/vol3_triage.py -f /evidence/mem.raw --os windows --hunt-injection --dump-suspect
bash scripts/ebpf_rootkit_hunt.sh # Linux live/IR eBPF rootkit hunt (LinkPro-aware)
# 3. Windows event-log fast timeline + Sigma hunt:
bash scripts/evtx_hunt.sh -d /evidence/C/Windows/System32/winevt/Logs -o /evidence/timeline
# 4. Anti-forensics: timestomp / USN tamper detection from $MFT + $J:
python3 scripts/timestomp_detect.py --mft /evidence/mft.csv --usn /evidence/usn.csv
# 5. Cloud breach (identity-plane first):
python3 scripts/cloud_ir_collect.py aws --collect-cloudtrail --contain-key AKIA... --enforce-imdsv2
# 6. Ransomware on a Windows host (rapid scope, do BEFORE eradication):
powershell -ep bypass -File scripts/ransomware_triage.ps1 -OutDir C:\IRIR is defensive; "OPSEC" below = handling rules that keep evidence admissible and avoid tipping off an adversary who may be monitoring (UNC3944 joins IR bridges in real time).
| Technique | Telemetry / IOC | Detection (Sigma / EDR) | OPSEC / evidence note |
|---|---|---|---|
| Live triage | New service/scheduled task for collector; large file writes to evidence path | Baseline expected DFIR tooling; alert on unsigned collectors | Collect RAM first; never write evidence to the suspect volume; hash everything |
| Velociraptor abuse | velociraptor.exe svc <0.73.5; MSI from Azure Blob; relaunch after isolation | Sigma: unexpected Velociraptor service install; CVE-2025-6264 UpdateConfig | Treat unexpected Velociraptor as persistence, not your tooling |
| Memory injection | RX/RWX private VAD not file-backed (malfind); reparented svchost | Vol3 malfind/hollowprocesses; EDR unbacked-exec | Document plugin+offset provenance; keep raw dump read-only |
| eBPF rootkit | bpf_override_return; getdents/sys_bpf hooks; XDP magic-packet (win=54321); /etc/ld.so.preload | linux.ebpf vs baseline; ss(netlink) vs /proc/net diff; YARA MAL_LinkPro_* | bpftool/ps/ss lie on host — acquire RAM out-of-band (hypervisor/LiME RO) |
| EVTX clearing | 1102 (Security cleared), 104 (System cleared), gaps in EventRecordID | Chainsaw/Hayabusa Sigma; alert on 1102/104 | Pull EVTX from VSS/disk image, not the tampered live log |
| Timestomp | $SI ≠ $FN create time; sub-second zeros; USN FILE_CREATE mismatch | timestomp_detect.py; MFTECmd Created0x10 vs Created0x30 | $FN is harder to forge — anchor truth to it + USN/$LogFile |
| Cloud cred theft | InstanceCredentialExfiltration.OutsideAWS; impossible-travel sign-in; CloudTrail StopLogging | GuardDuty findings; Sentinel KQL risky sign-ins | Snapshot+immutable-export BEFORE remediation; logs to a SIEM the attacker can't reach |
| Ransomware/ESXi | Mass file rename/ext change; vCenter/ESXi SSH on; bulk vim-cmd VM power-off | SIEM: high-volume VM power-off from one host; vpxuser anomalies | Image before decrypt attempts; preserve note + sample; assume comms compromised |
dangling_commit_finder.py, git fsck via git_safe), GH Archive + Wayback CDX + live Events API (gharchive_recover.py); hypothesis→verify-at-source (evidence_kit)→adversarial-check→report, attribution-with-confidence, BigQuery kept optional.© hypnguyen1209, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 16 other files (scripts, references) in skills/incident-response of hypnguyen1209/offensive-claude.
Open the folder on GitHubat commit a506ad3
Incident Response next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Incident Response this skillhypnguyen1209/offensive-claude | 388 | — | ~2.5k | Automated safety check: Pass | MIT | |
| Forensics OsqueryAgentSecOps/SecOpsAgentKit | 220 | 1 repos | ~4.9k | Automated safety check: Notes | Custom licence | |
| Ir VelociraptorAgentSecOps/SecOpsAgentKit | 220 | 1 repos | ~3.1k | Automated safety check: Pass | Custom licence | |
| Analyzing Memory Forensics With Lime And Volatilitymukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~631 | Automated safety check: Pass | Apache-2.0 | |
| Analyzing Outlook Pst For Email Forensicsmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~3.2k | Automated safety check: Pass | Apache-2.0 | |
| Extracting Memory Artifacts With Rekallmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~642 | Automated safety check: Pass | Apache-2.0 |
AgentSecOps/SecOpsAgentKit
SQL-powered forensic investigation and system interrogation using osquery to query operating systems as relational databases.
AgentSecOps/SecOpsAgentKit
Endpoint visibility, digital forensics, and incident response using Velociraptor Query Language (VQL) for evidence collection and threat hunting at scale.
mukul975/Anthropic-Cybersecurity-Skills
Performs Linux memory acquisition using LiME (Linux Memory Extractor) kernel module and analysis with Volatility 3 framework.
mukul975/Anthropic-Cybersecurity-Skills
Parse Microsoft Outlook PST and OST files using libpff and pst-utils to extract message content, headers, attachments, deleted items, and MAPI metadata, including recovery of items from the…
mukul975/Anthropic-Cybersecurity-Skills
Uses Rekall memory forensics framework to analyze memory dumps for process hollowing, injected code via VAD anomalies, hidden processes, and rootkit detection.
mukul975/Anthropic-Cybersecurity-Skills
Analyze volatile memory (RAM) dumps using the Volatility 3 framework to extract running processes, network connections, loaded modules, credentials, and encryption keys, and to detect process…
hypnguyen1209/offensive-claude
A skill your agent uses when assessing cryptography — TLS/PKI auditing, RSA/ECC key attacks, ECDSA nonce lattice recovery, symmetric/AEAD misuse, JWT/JOSE forgery, hash cracking, post-quantum…
hypnguyen1209/offensive-claude
A skill your agent uses when reverse-engineering or detecting malware — static triage + capa/YARA-X, emulation/DBI/.NET unpacking, dynamic/fileless/Volatility 3 memory analysis, C2 config extraction…
hypnguyen1209/offensive-claude
A skill your agent uses when mapping a target's external attack surface or gathering OSINT — subdomain enumeration, attack-surface mapping (httpx/katana/JS secrets), subdomain takeover…
hypnguyen1209/offensive-claude
A skill your agent uses when hunting threats or engineering detections — ATT&CK Detection-Strategies, Sigma + correlation with Detection-as-Code CI, Windows endpoint hunting…
hypnguyen1209/offensive-claude
A skill your agent uses when starting an engagement, before exploitation, or whenever the attack surface changes — build/validate the threat model and detect drift (new unreviewed surface) before…
hypnguyen1209/offensive-claude
A skill your agent uses when creating or editing a skill in this offensive-claude repo — for the SKILL.md conventions (trigger descriptions, technique map, runnable scripts, OPSEC/detection…
Categories
A skill your agent uses when responding to or forensically investigating an incident — triage acquisition (Velociraptor/KAPE), Volatility 3 memory forensics, Chainsaw/Hayabusa EVTX timelining…. Incident Response is an agent skill from hypnguyen1209/offensive-claude.
Incident Response fits situations like: forensically investigating an incident — triage acquisition (Velociraptor/KAPE); volatility 3 memory forensics; chainsaw/Hayabusa EVTX timelining; anti-forensics detection.
Run `npx skills add hypnguyen1209/offensive-claude --skill incident-response -a claude-code`. Or copy the skill folder (skills/incident-response in hypnguyen1209/offensive-claude) into .claude/skills/incident-response in your project. Claude Code loads it when a task matches its description.
Run `npx skills add hypnguyen1209/offensive-claude --skill incident-response -a codex`. Or copy the skill folder (skills/incident-response in hypnguyen1209/offensive-claude) into .agents/skills/incident-response in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add hypnguyen1209/offensive-claude --skill incident-response -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/incident-response, .gemini/skills/incident-response, .github/skills/incident-response and .opencode/skills/incident-response in your project.
Going by SKILL.md and its folder, Incident Response needs Python, a shell and PowerShell for the scripts in its folder and the command-line tools its instructions call (python3 and bash). Our summary lists: Python 3; A Bash shell; PowerShell.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Incident Response is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.5k tokens (SKILL.md is roughly 9.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 13k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Incident Response: Forensics Osquery (AgentSecOps/SecOpsAgentKit, 220 stars), Ir Velociraptor (AgentSecOps/SecOpsAgentKit, 220 stars), Analyzing Memory Forensics With Lime And Volatility (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Analyzing Outlook Pst For Email Forensics (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
hypnguyen1209 (a GitHub user) maintains it in hypnguyen1209/offensive-claude, which has 388 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on September 28, 2026.
Source: hypnguyen1209/offensive-claude on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.