Agent skill

Performing Disk Forensics Investigation

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Conduct disk forensics investigations using forensic imaging, file system analysis, and timeline reconstruction, with tools such as FTK Imager, Autopsy, and The Sleuth Kit, for evidence acquisition…

Apache-2.0Auto-check passedSecurity

Install Performing Disk Forensics Investigation

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-disk-forensics-investigation -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills performing-disk-forensics-investigation --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/performing-disk-forensics-investigation .claude/skills/performing-disk-forensics-investigation && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
performing-disk-forensics-investigation
GitHub stars
34k
Token cost
~2.7k tokens
SKILL.md length
915 words
Files
4 (incl. scripts, references)
Skills in repo
644
Repo updated
First seen
Licence
Apache-2.0

At a glance

Conduct disk forensics investigations using forensic imaging, file system analysis, and timeline reconstruction, with tools such as FTK Imager, Autopsy, and The Sleuth Kit, for evidence acquisition…

  • Works in 6 steps: Secure and Document the Evidence → Create a Forensic Image → Analyze File System Structure → …
  • A security incident requires forensic analysis of persistent storage
  • SKILL.md covers When to Use, Prerequisites, Workflow and Key Concepts, plus 3 more sections
  • Runs Python scripts from its folder

What it does

Performing Disk Forensics Investigation is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Conduct disk forensics investigations using forensic imaging, file system analysis, and timeline reconstruction, with tools such as FTK Imager, Autopsy, and The Sleuth Kit, for evidence acquisition, deleted file recovery, and artifact examination. Use when a security incident requires forensic analysis of persistent storage or when evidence must be preserved for legal or HR proceedings.

Its SKILL.md is about 2.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/api-reference.md` and `scripts/agent.py`).

It sits in Security, covering Digital forensics. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • A security incident requires forensic analysis of persistent storage
  • Evidence must be preserved for legal

Example prompts

  • “/performing-disk-forensics-investigation”

Requirements

  • Python 3

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Secure and Document the Evidence
  2. Create a Forensic Image
  3. Analyze File System Structure
  4. Reconstruct the Timeline
  5. Recover and Analyze Artifacts
  6. Document Findings

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Performing Disk Forensics Investigation loads about 2.7k tokens when it runs, and up to ~3.2k if it reads all its reference files. Until then it costs about 107 tokens; SKILL.md has 915 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~107
When it runs · the whole SKILL.md, loaded when a task matches
~2.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 915 words, ~2,684 tokens.

Download SKILL.mdSave it as .claude/skills/performing-disk-forensics-investigation/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
performing-disk-forensics-investigation
description
Conduct disk forensics investigations using forensic imaging, file system analysis, and timeline reconstruction, with tools such as FTK Imager, Autopsy, and The Sleuth Kit, for evidence acquisition, deleted file recovery, and artifact examination. Use when a security incident requires forensic analysis of persistent storage or when evidence must be preserved for legal or HR proceedings.
domain
cybersecurity
subdomain
incident-response
tags
disk-forensics, forensic-imaging, evidence-acquisition, file-recovery, chain-of-custody
mitre_attack
T1486, T1490, T1070, T1078, T1005
version
1.0.0
author
mahipal
license
Apache-2.0
nist_csf
RS.MA-01, RS.MA-02, RS.AN-03, RC.RP-01

Performing Disk Forensics Investigation

When to Use

  • A security incident requires forensic analysis of a system's persistent storage
  • Evidence preservation is needed for potential legal proceedings or HR investigations
  • Deleted files, browser history, or application artifacts must be recovered
  • A timeline of user or adversary activity must be reconstructed from file system metadata
  • Malware persistence mechanisms stored on disk need identification and documentation

Do not use for volatile evidence (running processes, network connections); use memory forensics with Volatility instead.

Prerequisites

  • Forensic workstation with write-blocking hardware or software (Tableau T35u, Arsenal Image Mounter)
  • Forensic imaging software: FTK Imager, Guymager, or dd with dcfldd
  • Analysis platform: Autopsy, FTK (Forensic Toolkit), or X-Ways Forensics
  • Sufficient storage (2-3x the target drive size for image plus working copies)
  • Chain of custody forms and evidence bags for physical media
  • Hash verification tools for evidence integrity (SHA-256)

Workflow

Step 1: Secure and Document the Evidence

Before touching any storage media, establish chain of custody:

  • Photograph the system, noting serial numbers, labels, and cable connections
  • Document the evidence source: device type, make, model, serial number, capacity
  • Complete chain of custody form with date, time, handler name, and reason for acquisition
  • Use a hardware write blocker when connecting the evidence drive to the forensic workstation
Chain of Custody Record:
━━━━━━━━━━━━━━━━━━━━━━━
Case ID:          INC-2025-1547
Evidence ID:      EVD-001
Description:      Samsung 870 EVO 500GB SSD
Serial Number:    S5XXNJ0R912345
Source Host:      WKSTN-042
Acquired By:      [Analyst Name]
Date/Time:        2025-11-15T16:30:00Z
Write Blocker:    Tableau T35u (S/N: T35U-12345)
Step 2: Create a Forensic Image

Produce a bit-for-bit copy of the evidence drive:

Using FTK Imager (Windows):

  1. Connect evidence drive through write blocker
  2. File > Create Disk Image > Select source drive
  3. Choose E01 (Expert Witness Format) for compression and metadata
  4. Set destination path and evidence item information
  5. Enable "Verify images after they are created"
  6. Record source and image hash values

Using dcfldd (Linux):

bash
# Create raw image with hash verification
dcfldd if=/dev/sdb of=/evidence/WKSTN-042.dd \
  hash=sha256 hashlog=/evidence/WKSTN-042.sha256 \
  bs=4096 conv=noerror,sync

# Verify image integrity
sha256sum /evidence/WKSTN-042.dd
Imaging Summary:
Source Drive:    /dev/sdb (Samsung 870 EVO 500GB)
Image File:     WKSTN-042.E01
Image Format:   E01 (Expert Witness)
Source Hash:     SHA-256: a1b2c3d4e5f6...
Image Hash:      SHA-256: a1b2c3d4e5f6...  (MATCH)
Sectors Read:    976,773,168
Errors:          0
Duration:        47 minutes
Step 3: Analyze File System Structure

Open the forensic image in Autopsy or FTK and examine the file system:

  • Identify partition layout (MBR/GPT, NTFS/ext4/APFS partitions)
  • Examine the Master File Table (MFT) for NTFS or inode tables for ext4
  • Identify deleted files and directories (marked as unallocated but not yet overwritten)
  • Recover files from unallocated space using file carving
  • Examine alternate data streams (NTFS ADS) for hidden data

Key Windows Artifacts to Examine:

User Activity:
- NTUSER.DAT (registry hive per user)
- UsrClass.dat (shellbags, file access history)
- Recent files: %AppData%\Microsoft\Windows\Recent\
- Jump lists: %AppData%\Microsoft\Windows\Recent\AutomaticDestinations\

Program Execution:
- Prefetch: C:\Windows\Prefetch\*.pf
- Amcache: C:\Windows\appcompat\Programs\Amcache.hve
- SRUM: C:\Windows\System32\SRU\SRUDB.dat
- ShimCache: SYSTEM registry hive

Persistence:
- Scheduled Tasks: C:\Windows\System32\Tasks\
- Startup folders: %AppData%\Microsoft\Windows\Start Menu\Programs\Startup\
- Services: SYSTEM registry hive

Network:
- WLAN profiles: C:\ProgramData\Microsoft\Wlansvc\Profiles\
- Browser history: Chrome, Firefox, Edge profile directories
Step 4: Reconstruct the Timeline

Build a comprehensive timeline of file system activity:

Using Autopsy Timeline Module:

  1. Generate timeline from all available sources (MFT, event logs, browser history, prefetch)
  2. Filter to the investigation timeframe
  3. Identify clusters of activity correlating with the incident
  4. Document the sequence of attacker actions based on file creation, modification, and access timestamps

Using The Sleuth Kit (command line):

bash
# Generate body file from NTFS image
fls -r -m / WKSTN-042.dd > bodyfile.txt

# Create timeline from body file
mactime -b bodyfile.txt -d > timeline.csv

# Filter timeline to investigation period
grep "2025-11-15" timeline.csv | sort > incident_timeline.csv
Step 5: Recover and Analyze Artifacts

Extract and analyze specific forensic artifacts:

  • Prefetch files: Parse with PECmd to determine program execution times and loaded DLLs
  • Event logs: Parse with EvtxECmd for Windows XML Event Logs
  • Registry: Parse with RegRipper or Registry Explorer for user activity and system configuration
  • Browser artifacts: Parse with Hindsight (Chrome), KAPE, or DB Browser for SQLite databases
  • USB device history: Extract from SYSTEM\CurrentControlSet\Enum\USBSTOR registry key
  • $MFT analysis: Parse with MFTECmd for detailed file metadata including $SI and $FN timestamps
Step 6: Document Findings

Compile a forensic analysis report suitable for legal proceedings:

  • Maintain evidence integrity documentation (hash chain)
  • Document every tool used and its version
  • Record all analysis steps in a reproducible manner
  • Present findings factually without conjecture
  • Clearly distinguish between facts (observed data) and interpretations (analyst conclusions)
Show full SKILL.md (370 more words)Show less

Key Concepts

TermDefinition
Forensic ImageBit-for-bit copy of storage media that preserves all data including deleted files and unallocated space
Write BlockerHardware or software device that prevents any modification to evidence media during acquisition
E01 FormatExpert Witness Format used by EnCase and FTK; supports compression, metadata, and built-in hash verification
File CarvingRecovery technique that searches unallocated disk space for file headers and footers to reconstruct deleted files
MFT (Master File Table)NTFS metadata structure containing entries for every file and directory, including deleted entries
MAC TimestampsModified, Accessed, Created timestamps on files used for timeline reconstruction (NTFS also has Entry Modified)
PrefetchWindows artifact recording program execution metadata; contains execution count, timestamps, and loaded DLLs
Unallocated SpaceDisk sectors not assigned to any file; may contain remnants of deleted files recoverable through carving

Tools & Systems

  • FTK Imager: Free forensic imaging tool supporting E01, AFF, and raw formats with built-in hash verification
  • Autopsy: Open-source digital forensics platform built on The Sleuth Kit for comprehensive disk analysis
  • KAPE (Kroll Artifact Parser and Extractor): Triage collection and parsing tool for rapid artifact extraction
  • X-Ways Forensics: Commercial forensic analysis tool known for speed and efficiency on large datasets
  • Eric Zimmerman's Tools: Suite of free forensic parsers (PECmd, MFTECmd, EvtxECmd, RegRipper) for Windows artifacts

Common Scenarios

Scenario: Employee Data Theft Investigation

Context: An employee submitted a resignation and is suspected of copying proprietary files to a USB drive before departing. HR requests a forensic investigation of the employee's workstation.

Approach:

  1. Image the workstation disk using FTK Imager with a write blocker
  2. Parse USB device history from SYSTEM registry to identify connected devices
  3. Examine ShellBags and Jump Lists for evidence of file browsing and copying to removable media
  4. Parse LNK files in the Recent folder to identify recently accessed documents
  5. Analyze browser history for personal cloud storage uploads (Google Drive, Dropbox)
  6. Build a timeline correlating USB connections with file access events

Pitfalls:

  • Failing to image the drive before the IT department reassigns the workstation
  • Not checking cloud storage browser history alongside USB evidence
  • Overlooking Volume Shadow Copies that may contain earlier versions of deleted files
  • Presenting analysis conclusions as fact without supporting evidence documentation

Output Format

DISK FORENSICS INVESTIGATION REPORT
=====================================
Case ID:          INC-2025-1547
Evidence:         EVD-001 (Samsung 870 EVO 500GB SSD)
Examiner:         [Name]
Date of Analysis: 2025-11-16

EVIDENCE INTEGRITY
Source Hash:      SHA-256: a1b2c3d4e5f6...
Image Hash:       SHA-256: a1b2c3d4e5f6... (VERIFIED MATCH)
Write Blocker:    Tableau T35u

PARTITION LAYOUT
Partition 1:  NTFS  100 MB   (System Reserved)
Partition 2:  NTFS  465 GB   (C: - OS and Data)
Partition 3:  NTFS  500 MB   (Recovery)

KEY FINDINGS
1. [Timestamp] - Malware dropper created in %TEMP% (update.exe)
2. [Timestamp] - Scheduled task "WindowsUpdate" created for persistence
3. [Timestamp] - Prefetch shows 14 executions of update.exe
4. [Timestamp] - USB device "Kingston DataTraveler" connected
5. [Timestamp] - 847 files copied to E:\ drive (ShellBag evidence)

RECOVERED ARTIFACTS
- 3 deleted malware samples recovered from unallocated space
- Browser history showing C2 panel access
- Registry evidence of disabled security software

TIMELINE
[Chronological event listing with timestamps and evidence sources]

TOOLS USED
- FTK Imager 4.7.1 (imaging)
- Autopsy 4.21.0 (analysis)
- PECmd 1.5.0 (prefetch parsing)
- MFTECmd 1.2.2 (MFT analysis)

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts, references) in skills/performing-disk-forensics-investigation of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • references/api-reference.md
  • scripts/agent.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Performing Disk Forensics Investigation next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Performing Disk Forensics Investigation compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Performing Disk Forensics Investigation this skillmukul975/Anthropic-Cybersecurity-Skills34k—~2.7kAutomated safety check: PassApache-2.0
Oss ForensicsTommy-yw/RunbookHermes5463 repos~5kAutomated safety check: PassMIT
Ctf Malwareljagiello/ctf-skills3.4k—~2.1kAutomated safety check: NotesMIT
Dfirtransilienceai/communitytools563—~1.5kAutomated safety check: PassMIT
TShark Traffic AnalysisAgentSecOps/SecOpsAgentKit2201 repos~4.8kAutomated safety check: NotesCustom licence
Runtime Memory Sample Acquisitiondslsdzc/rev-skills135—~2kAutomated safety check: PassApache-2.0

Similar skills

  • Oss Forensics

    Tommy-yw/RunbookHermes

    Supply chain investigation, evidence recovery, and forensic analysis for GitHub repositories.

    546 GitHub starsUsed in 3 repos~5k tokens
    SecurityAuto-check passed
  • Ctf Malware

    ljagiello/ctf-skills

    Provides malware analysis and network traffic techniques for CTF challenges.

    3.4k GitHub stars~2.1k tokensUpdated 26 days ago
    SecurityAuto-check: notes
  • Dfir

    transilienceai/communitytools

    Digital forensics and incident response - Windows event log analysis, PCAP forensics, filesystem artifact analysis, AD attack detection, and timeline correlation.

    563 GitHub stars~1.5k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • TShark Traffic Analysis

    AgentSecOps/SecOpsAgentKit

    Guides authorized packet capture and analysis with TShark, Wireshark's command-line tool, for security investigations, malware detection and forensic examination of network traffic.

    220 GitHub starsUsed in 1 repo~4.8k tokens
    SecurityAuto-check: notes
  • Captures an analyzable sample from a live system when the target leaves no file on disk, by finding abnormal executable memory and the execution context that reached it.

    135 GitHub stars~2k tokensUpdated 5 days ago
    SecurityAuto-check passed
  • Digital Forensics

    zhaoxuya520/reverse-skill

    A skill your agent uses for authorized digital forensics including memory dumps, disk timelines, PCAP investigation, artifact triage, and IR evidence preservation.

    41k GitHub starsUsed in 2 repos~389 tokens
    SecurityAuto-check: warnings

More from mukul975/Anthropic-Cybersecurity-Skills

All 644 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Performing Disk Forensics Investigation

What does Performing Disk Forensics Investigation do?

Conduct disk forensics investigations using forensic imaging, file system analysis, and timeline reconstruction, with tools such as FTK Imager, Autopsy, and The Sleuth Kit, for evidence acquisition…. Performing Disk Forensics Investigation is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Conduct disk forensics investigations using forensic imaging, file system analysis, and timeline reconstruction, with tools such as FTK Imager, Autopsy, and The Sleuth Kit, for evidence acquisition, deleted file recovery, and artifact examination.

When should I use Performing Disk Forensics Investigation?

Performing Disk Forensics Investigation fits situations like: A security incident requires forensic analysis of persistent storage; evidence must be preserved for legal.

How do I install Performing Disk Forensics Investigation in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-disk-forensics-investigation -a claude-code`. Or copy the skill folder (skills/performing-disk-forensics-investigation in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/performing-disk-forensics-investigation in your project. Claude Code loads it when a task matches its description.

How do I install Performing Disk Forensics Investigation in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-disk-forensics-investigation -a codex`. Or copy the skill folder (skills/performing-disk-forensics-investigation in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/performing-disk-forensics-investigation in your project. Codex loads it when a task matches its description.

Can I use Performing Disk Forensics Investigation in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-disk-forensics-investigation -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/performing-disk-forensics-investigation, .gemini/skills/performing-disk-forensics-investigation, .github/skills/performing-disk-forensics-investigation and .opencode/skills/performing-disk-forensics-investigation in your project.

What does Performing Disk Forensics Investigation need to run?

Going by SKILL.md and its folder, Performing Disk Forensics Investigation needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Performing Disk Forensics Investigation access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Performing Disk Forensics Investigation safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Performing Disk Forensics Investigation use?

Performing Disk Forensics Investigation is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Performing Disk Forensics Investigation use?

About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 534 tokens, read only when the agent opens those files.

What are the alternatives to Performing Disk Forensics Investigation?

Skills that share tags, products or a category with Performing Disk Forensics Investigation: Oss Forensics (Tommy-yw/RunbookHermes, 546 stars), Ctf Malware (ljagiello/ctf-skills, 3.4k stars), Dfir (transilienceai/communitytools, 563 stars) and TShark Traffic Analysis (AgentSecOps/SecOpsAgentKit, 220 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Performing Disk Forensics Investigation?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 34,116 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.