Agent skill

Breach Forensics

by mukul975 in mukul975/Privacy-Data-Protection-Skills

Conducts digital forensics investigations following a personal data breach, covering evidence preservation, chain of custody documentation, log analysis, scope determination, and root cause analysis.

Apache-2.0Auto-check passedSecurity

Install Breach Forensics

skills CLI
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill breach-forensics -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Privacy-Data-Protection-Skills breach-forensics --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/breach-forensics .claude/skills/breach-forensics && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
breach-forensics
GitHub stars
295
Token cost
~3.1k tokens
SKILL.md length
1,465 words
Files
5 (incl. scripts, references, assets)
Skills in repo
278
Repo updated
First seen
Licence
Apache-2.0

At a glance

Conducts digital forensics investigations following a personal data breach, covering evidence preservation, chain of custody documentation, log analysis, scope determination, and root cause analysis.

  • Works in 4 steps: Identify All Compromised Systems → Determine Accessed Data → Determine Exfiltration → …
  • Tasks that involve Digital forensics
  • SKILL.md covers Overview, Evidence Preservation Protocol, Chain of Custody Documentation and Log Analysis Methodology, plus 3 more sections
  • Runs Python scripts from its folder

What it does

Breach Forensics is an agent skill from mukul975/Privacy-Data-Protection-Skills. Conducts digital forensics investigations following a personal data breach, covering evidence preservation, chain of custody documentation, log analysis, scope determination, and root cause analysis. References industry-standard tools including Splunk, ELK Stack, and Wireshark. Provides forensic workflow from initial evidence collection through final investigation report. Keywords: digital forensics, breach investigation, evidence preservation, chain of custody, root cause analysis, Splunk, ELK, Wireshark.

Its SKILL.md is about 3.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).

It sits in Security, covering Digital forensics, Network security and Root cause analysis. It works with Wireshark and Splunk. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Digital forensics
  • Tasks that involve Network security
  • Tasks that involve Root cause analysis

Example prompts

  • “Use the breach-forensics skill to conduct digital forensics investigations following a personal data breach, covering evidence preservation, chain…”
  • “/breach-forensics”

Requirements

  • Python 3

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Identify All Compromised Systems
  2. Determine Accessed Data
  3. Determine Exfiltration
  4. Establish Breach Timeline

What it can do on your machine

Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Breach Forensics loads about 3.1k tokens when it runs, and up to ~6.9k if it reads all its reference files. Until then it costs about 132 tokens; SKILL.md has 1,465 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~132
When it runs · the whole SKILL.md, loaded when a task matches
~3.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~6.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 1,465 words, ~3,108 tokens.

Download SKILL.mdSave it as .claude/skills/breach-forensics/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
breach-forensics
description
Conducts digital forensics investigations following a personal data breach, covering evidence preservation, chain of custody documentation, log analysis, scope determination, and root cause analysis. References industry-standard tools including Splunk, ELK Stack, and Wireshark. Provides forensic workflow from initial evidence collection through final investigation report. Keywords: digital forensics, breach investigation, evidence preservation, chain of custody, root cause analysis, Splunk, ELK, Wireshark.
license
Apache-2.0
metadata.author
mukul975
metadata.version
1.0
metadata.domain
privacy
metadata.subdomain
data-breach-response
metadata.tags
digital-forensics, breach-investigation, evidence-preservation, chain-of-custody, root-cause

Conducting Breach Investigation Forensics

Overview

When a personal data breach is confirmed, a thorough forensic investigation is essential to determine the breach scope (which personal data and data subjects were affected), the attack vector, the timeline of unauthorized activity, and the root cause. The investigation findings directly feed into the Art. 33 supervisory authority notification, the Art. 34 data subject communication, and the post-breach remediation plan. This skill provides the complete forensic investigation workflow, evidence handling procedures, and analysis techniques.

Evidence Preservation Protocol

Golden Rule: Preserve First, Analyze Second

The first priority upon breach confirmation is to preserve volatile evidence before it is overwritten or destroyed. Evidence must be collected in order of volatility:

  1. CPU registers and cache — captured via live memory acquisition tools (Volatility, WinPmem, LiME).
  2. Memory (RAM) contents — full memory dump of affected systems. Contains running processes, network connections, encryption keys, and malware artifacts that may not exist on disk.
  3. Network connections and routing tables — current active connections may reveal command-and-control (C2) infrastructure or ongoing data exfiltration.
  4. Running processes and services — process trees, loaded DLLs, open file handles, and user context.
  5. Disk contents — forensic disk images (bit-for-bit copies) of affected system storage. Use write blockers for physical media.
  6. Log files — system logs, application logs, security logs, database audit logs. Prioritize logs that may be subject to rotation or overwrite.
  7. Network traffic captures — packet captures (PCAP) from network taps, SPAN ports, or inline capture points.
  8. External evidence — cloud service logs (AWS CloudTrail, Azure Activity Log), SaaS audit logs, third-party vendor logs.
Forensic Image Acquisition
System TypeToolMethodHash Verification
Windows serverFTK Imager 4.7Bit-for-bit disk image to external write-blocked storageSHA-256 + MD5 dual hash
Linux serverdc3ddBit-for-bit using /dev/sda source to external storageSHA-256 hash with dcfldd verification
AWS EC2 instanceAWS CLI + EBS snapshotCreate EBS snapshot, then convert to forensic imageSHA-256 of snapshot export
Databasepg_dump (logical) + disk imageLogical export for data analysis + physical disk image for artifact recoverySHA-256 of both outputs
Mobile deviceCellebrite UFED / GrayKeyPhysical extraction where legally permittedSHA-256 of extraction package
Cloud storage (S3)AWS CLI sync with versioningDownload all object versions including deleted objectsSHA-256 of manifest

Chain of Custody Documentation

Every piece of evidence must be tracked from acquisition through analysis to storage using a formal chain of custody record:

Evidence Tracking Fields
FieldDescription
Evidence IDUnique identifier: SPG-BREACH-2026-003-EV-001
DescriptionFull RAM dump of db-prod-eu-west-01 (PostgreSQL primary)
Date/time acquired13 March 2026, 15:47 UTC
Acquired byThomas Brenner, CISO, Stellar Payments Group
Acquisition toolWinPmem 4.0 — Memory acquisition
Hash at acquisitionSHA-256: a3f8b2c1d9e... (full hash recorded in evidence log)
Storage locationForensic evidence vault, Building A, Room 104, Safe #3, Shelf B
Access logAll access to evidence is logged with name, date, time, and purpose
Chain of Custody Transfer Record
Transfer #Date/TimeReleased ByReceived ByPurposeHash Verified
113 March 2026, 16:00 UTCThomas Brenner (CISO)Mandiant IR Analyst (Sarah Mitchell)Forensic analysisYes — SHA-256 match
220 March 2026, 10:00 UTCSarah Mitchell (Mandiant)Thomas Brenner (CISO)Return after analysisYes — SHA-256 match

Log Analysis Methodology

Tool Selection and Application
Splunk Enterprise Security
  • Use case: Centralized log correlation, timeline reconstruction, behavioral analysis.
  • Key searches for breach investigation:
    • Authentication events: index=auth sourcetype=okta:log action=authentication.login | stats count by user, result, client.ipAddress, client.geographicalContext.country
    • Database queries: index=database sourcetype=postgresql:audit query_type=SELECT table IN (customers, transactions, accounts) | stats count, values(query_text) by user, source_ip
    • Data exfiltration: index=network sourcetype=pan:traffic dest_zone=untrust bytes_sent>50000000 | stats sum(bytes_sent) by src_ip, dest_ip, app
ELK Stack (Elasticsearch, Logstash, Kibana)
  • Use case: Large-volume log ingestion, full-text search, visualization of access patterns.
  • Key queries for breach investigation:
    • Anomalous access timing: Filter by timestamp outside of business hours (before 07:00 or after 20:00 local time) against personal data system indices.
    • Geo-anomaly detection: Aggregate authentication source IPs by geolocation; flag countries not present in the 90-day baseline.
    • Volume anomaly: Aggregate data access events by user per hour; identify spikes exceeding 3 standard deviations above the 30-day mean.
Wireshark / tshark
  • Use case: Packet-level analysis of network traffic to/from compromised systems.
  • Key filters for breach investigation:
    • Identify data exfiltration: ip.src == 10.0.1.50 && tcp.dstport != 443 && frame.len > 1000 (non-HTTPS outbound from compromised host)
    • Identify C2 communication: dns.qry.name contains ".onion" || dns.qry.name contains "dga" (DNS queries to suspicious domains)
    • Reconstruct data transfers: Follow TCP streams to recover transferred file contents from PCAP captures.
Additional Tools
ToolPurposeApplication
Volatility 3Memory forensicsAnalyze RAM dumps for malware, injected code, credential harvesting
Autopsy / Sleuth KitDisk forensicsRecover deleted files, analyze file system timelines, extract artifacts
YARAMalware identificationScan disk images and memory dumps against malware signature rules
Plaso / log2timelineSuper-timeline creationCreate unified timeline from multiple evidence sources
ChainsawWindows event log analysisRapid triage of Windows EVTX logs using Sigma detection rules

Scope Determination Process

Step 1: Identify All Compromised Systems
  1. Starting from the initially identified compromised system, trace lateral movement through authentication logs, network connection logs, and endpoint detection alerts.
  2. For each system identified, determine whether it stores, processes, or transmits personal data by cross-referencing with the data processing inventory (Art. 30 records).
  3. Document each compromised system with: hostname, IP address, function, data classification, personal data categories stored, and estimated data subject count.
Show full SKILL.md (594 more words)Show less
Step 2: Determine Accessed Data
  1. For each compromised system containing personal data, analyze access logs to determine which specific tables, files, or records were accessed by the attacker.
  2. Distinguish between "system compromised" (attacker had access to the system) and "data accessed" (attacker actually queried or downloaded personal data).
  3. Apply the precautionary principle: if logs are insufficient to determine whether specific data was accessed, assume all data on the compromised system was potentially accessed.
Step 3: Determine Exfiltration
  1. Analyze network traffic logs for data transfers from compromised systems to external destinations during the breach window.
  2. Review DNS logs for DNS tunneling indicators (unusually long subdomain strings, high query volume to unusual domains).
  3. Check for encrypted channel usage (VPN, SSH, HTTPS) to external IPs not in the organization's approved destination list.
  4. Examine endpoint logs for evidence of compression, encryption, or staging of files prior to transfer.
  5. Report findings as: "Exfiltration confirmed," "No evidence of exfiltration (with confidence level)," or "Exfiltration cannot be ruled out."
Step 4: Establish Breach Timeline
  1. Determine the earliest evidence of unauthorized access (initial compromise date).
  2. Identify the timeline of attacker activity — what actions were taken and when.
  3. Determine when the breach was detected.
  4. Calculate the dwell time (time between initial compromise and detection).
  5. Document any periods where log coverage gaps prevent timeline reconstruction.

Root Cause Analysis

5-Whys Framework Applied to Data Breaches

Example: Stellar Payments Group Ransomware Incident

  1. Why did the ransomware execute? The attacker deployed ransomware using a compromised service account with administrative privileges on the database cluster.
  2. Why did the attacker have a compromised service account? The service account credentials were obtained from a spear-phishing email that an IT operations engineer clicked on 10 March 2026, which installed a credential-harvesting keylogger.
  3. Why did the phishing email reach the engineer? The email bypassed the email gateway because it was sent from a compromised legitimate domain and contained no detectable malicious payload (the link pointed to a legitimate-appearing login page).
  4. Why did the service account have administrative database privileges? The service account was originally created for a migration project in 2024 and was never decommissioned. Its privileges were not reviewed as part of the quarterly access review because service accounts were excluded from the review scope.
  5. Why were service accounts excluded from the access review? The access review policy defined its scope as "user accounts" and did not explicitly include service accounts, machine accounts, or API keys.

Root cause: Access review policy gap — service accounts excluded from periodic access certification, combined with stale elevated-privilege service account from completed project.

Investigation Report Structure

Section 1: Executive Summary
  • Breach type and classification
  • Date range of unauthorized activity
  • Number of affected data subjects and records
  • Root cause (one sentence)
  • Current status (contained/ongoing)
  • Key remediation recommendations
Section 2: Investigation Scope and Methodology
  • Investigation objectives
  • Evidence sources analyzed
  • Tools and techniques used
  • Investigation team members and roles
  • Timeline of investigation activities
Section 3: Findings
  • Detailed breach timeline with evidence citations
  • Systems compromised and personal data affected
  • Attack vector and technique (mapped to MITRE ATT&CK framework)
  • Exfiltration assessment
  • Root cause analysis
Section 4: Impact Assessment
  • Data subjects affected (count and categories)
  • Personal data compromised (categories and sensitivity)
  • Risk assessment for Art. 33/34 notification purposes
  • Regulatory exposure assessment
Section 5: Remediation Recommendations
  • Immediate actions (already taken)
  • Short-term actions (within 30 days)
  • Medium-term actions (within 90 days)
  • Long-term systemic improvements
Section 6: Evidence Inventory
  • Complete list of all evidence collected
  • Chain of custody records
  • Hash verification log
  • Evidence retention and disposal schedule

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/breach-forensics of mukul975/Privacy-Data-Protection-Skills.

  • SKILL.md
  • assets/template.md
  • references/standards.md
  • references/workflows.md
  • scripts/process.py

Open the folder on GitHubat commit 9b2ef9e

Compare with similar skills

Breach Forensics next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Breach Forensics compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Breach Forensics this skillmukul975/Privacy-Data-Protection-Skills295—~3.1kAutomated safety check: PassApache-2.0
Performing Network Packet Capture Analysismukul975/Anthropic-Cybersecurity-Skills34k—~2.3kAutomated safety check: PassApache-2.0
TShark Traffic AnalysisAgentSecOps/SecOpsAgentKit2201 repos~4.8kAutomated safety check: NotesCustom licence
Network Covert Channel Analysismukul975/Anthropic-Cybersecurity-Skills34k—~2kAutomated safety check: PassApache-2.0
Dfirtransilienceai/communitytools562—~1.5kAutomated safety check: PassMIT
Protocol Reverse Engineeringwshobson/agents40k8 repos~3.2kAutomated safety check: PassMIT

Similar skills

  • Performing Network Packet Capture Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Perform forensic analysis of network packet captures (PCAP/PCAPNG) using Wireshark, tshark, and tcpdump to reconstruct network communications, extract transferred files, identify malicious traffic…

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • TShark Traffic Analysis

    AgentSecOps/SecOpsAgentKit

    Guides authorized packet capture and analysis with TShark, Wireshark's command-line tool, for security investigations, malware detection and forensic examination of network traffic.

    220 GitHub starsUsed in 1 repo~4.8k tokens
    SecurityAuto-check: notes
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Dfir

    transilienceai/communitytools

    Digital forensics and incident response - Windows event log analysis, PCAP forensics, filesystem artifact analysis, AD attack detection, and timeline correlation.

    562 GitHub stars~1.5k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Master network protocol reverse engineering including packet analysis, protocol dissection, and custom protocol documentation.

    40k GitHub starsUsed in 8 repos~3.2k tokens
    SecurityAuto-check passed
  • Detecting Arp Poisoning In Network Traffic

    mukul975/Anthropic-Cybersecurity-Skills

    Detect Layer 2 ARP poisoning/spoofing by deploying ARPWatch, Dynamic ARP Inspection (DAI), Wireshark packet analysis, and custom Python monitoring scripts that flag gratuitous ARP floods, IP-to-MAC…

    34k GitHub stars~3.8k tokensUpdated 1 mo ago
    SecurityAuto-check: notes

More from mukul975/Privacy-Data-Protection-Skills

All 278 skills in this repo
  • Age Gating Services

    mukul975/Privacy-Data-Protection-Skills

    Implements age-gating mechanisms for online services to restrict access based on user age.

    295 GitHub stars~3.7k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Data Retention

    mukul975/Privacy-Data-Protection-Skills

    Manages AI model retention and machine unlearning requirements.

    295 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • Dpia Mitigation Plan

    mukul975/Privacy-Data-Protection-Skills

    Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).

    295 GitHub stars~846 tokensUpdated 6 mo ago
    Auto-check passed
  • Gdpr Accountability

    mukul975/Privacy-Data-Protection-Skills

    Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.

    295 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • Pia Threshold Screening

    mukul975/Privacy-Data-Protection-Skills

    Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.

    295 GitHub stars~880 tokensUpdated 6 mo ago
    Auto-check passed
  • Retention Schedule

    mukul975/Privacy-Data-Protection-Skills

    Designs and implements data retention schedules compliant with GDPR Article 5(1)(e) storage limitation principle.

    295 GitHub stars~3.3k tokensUpdated 6 mo ago
    Auto-check passed

Works with

Categories

Questions about Breach Forensics

What does Breach Forensics do?

Conducts digital forensics investigations following a personal data breach, covering evidence preservation, chain of custody documentation, log analysis, scope determination, and root cause analysis. Breach Forensics is an agent skill from mukul975/Privacy-Data-Protection-Skills. Conducts digital forensics investigations following a personal data breach, covering evidence preservation, chain of custody documentation, log analysis, scope determination, and root cause analysis.

When should I use Breach Forensics?

Breach Forensics fits situations like: tasks that involve Digital forensics; tasks that involve Network security; tasks that involve Root cause analysis.

How do I install Breach Forensics in Claude Code?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill breach-forensics -a claude-code`. Or copy the skill folder (skills/privacy/breach-forensics in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/breach-forensics in your project. Claude Code loads it when a task matches its description.

How do I install Breach Forensics in Codex?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill breach-forensics -a codex`. Or copy the skill folder (skills/privacy/breach-forensics in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/breach-forensics in your project. Codex loads it when a task matches its description.

Can I use Breach Forensics in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill breach-forensics -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/breach-forensics, .gemini/skills/breach-forensics, .github/skills/breach-forensics and .opencode/skills/breach-forensics in your project.

What does Breach Forensics need to run?

Going by SKILL.md and its folder, Breach Forensics needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Breach Forensics access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Breach Forensics safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Breach Forensics use?

Breach Forensics is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Breach Forensics use?

About 3.1k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.8k tokens, read only when the agent opens those files.

What are the alternatives to Breach Forensics?

Skills that share tags, products or a category with Breach Forensics: Performing Network Packet Capture Analysis (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), TShark Traffic Analysis (AgentSecOps/SecOpsAgentKit, 220 stars), Network Covert Channel Analysis (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Dfir (transilienceai/communitytools, 562 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Breach Forensics?

mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 295 GitHub stars. The repository holds 278 skills in this directory. The repository was last updated on March 16, 2026.

Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.