Agent skill

Forensics Disk

by MuWinds in MuWinds/BUUCTF_Agent

磁盘取证分析技术,涵盖 NTFS/FAT/ext 文件系统解析、文件恢复、时间线分析、日志挖掘等实战技能. An agent skill from MuWinds/BUUCTF_Agent.

Apache-2.0Auto-check: warningsSecurity

Install Forensics Disk

The automated check flagged lines worth reading first. See the safety section below.

skills CLI
$ npx skills add MuWinds/BUUCTF_Agent --skill forensics-disk -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install MuWinds/BUUCTF_Agent forensics-disk --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/MuWinds/BUUCTF_Agent.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/forensics-disk .claude/skills/forensics-disk && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
forensics-disk
GitHub stars
267
Token cost
~1k tokens
SKILL.md length
194 words
Files
1
Skills in repo
3
Repo updated
First seen
Licence
Apache-2.0

At a glance

磁盘取证分析技术,涵盖 NTFS/FAT/ext 文件系统解析、文件恢复、时间线分析、日志挖掘等实战技能. An agent skill from MuWinds/BUUCTF_Agent.

  • Works in 5 steps: 镜像挂载:使用 mount -o loop,ro 只读挂载镜像,或用 FTK… → 文件系统识别:fsstat 或 file -s 确认文件系统类型和参数 → 目录浏览:fls -r 递归列出所有文件(含已删除),istat 查看… → …
  • Security work in your project
  • SKILL.md covers 整体分析流程, NTFS 文件系统, FAT 文件系统 and ext4 文件系统, plus 3 more sections
  • Calls python3

What it does

Forensics Disk is an agent skill from MuWinds/BUUCTF_Agent. 磁盘取证分析技术,涵盖 NTFS/FAT/ext 文件系统解析、文件恢复、时间线分析、日志挖掘等实战技能。

Its SKILL.md is about 1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security. The repository describes itself as: 专为CTF设计的可扩展AI Agent,可自动解CTF题,也能与用户协作交互解题~. The licence is Apache-2.0.

When your agent uses it

  • Security work in your project

Example prompts

  • “/forensics-disk”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. 镜像挂载:使用 mount -o loop,ro 只读挂载镜像,或用 FTK Imager / Autopsy 加载
  2. 文件系统识别:fsstat 或 file -s 确认文件系统类型和参数
  3. 目录浏览:fls -r 递归列出所有文件(含已删除),istat 查看 inode/MFT 详情
  4. 关键文件提取:icat 按 inode/MFT 编号提取文件内容
  5. 时间线构建:mactime 从 MAC 时间戳生成完整活动时间线

What it can do on your machine

Read from SKILL.md and the folder at commit 95cc9e0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Forensics Disk loads about 1k tokens when it runs. Until then it costs about 17 tokens; SKILL.md has 194 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~17
When it runs · the whole SKILL.md, loaded when a task matches
~1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: warnings

The automated check found patterns that need a careful read before installing.

  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:148
    - Cookie:`%LOCALAPPDATA%\Google\Chrome\User Data\Default\Cookies`
  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:155
    - Cookie:`cookies.sqlite`

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from MuWinds/BUUCTF_Agent at commit 95cc9e0, republished under its Apache-2.0 licence (© MuWinds). 194 words, ~1,043 tokens.

Download SKILL.mdSave it as .claude/skills/forensics-disk/SKILL.md (or your agent's skills folder).
name
forensics-disk
description
磁盘取证分析技术,涵盖 NTFS/FAT/ext 文件系统解析、文件恢复、时间线分析、日志挖掘等实战技能。
tags
ntfs, fat, ext4, file-recovery, timeline, windows-event

磁盘取证分析方法论

整体分析流程

  1. 镜像挂载:使用 mount -o loop,ro 只读挂载镜像,或用 FTK Imager / Autopsy 加载
  2. 文件系统识别:fsstat 或 file -s 确认文件系统类型和参数
  3. 目录浏览:fls -r 递归列出所有文件(含已删除),istat 查看 inode/MFT 详情
  4. 关键文件提取:icat 按 inode/MFT 编号提取文件内容
  5. 时间线构建:mactime 从 MAC 时间戳生成完整活动时间线

NTFS 文件系统

MFT (Master File Table)
  • 每个文件/目录对应一个 MFT 记录,编号从 0 开始
  • $MFT (0)、$MFTMirr (1)、$LogFile (2)、$Volume (3)、$AttrDef (4)、$Root (5)、$Bitmap (6)、$Boot (7)
  • 常用命令:
    bash
    istat -f ntfs image.dd <MFT编号>   # 查看 MFT 记录详情
    icat -f ntfs image.dd <MFT编号>    # 提取文件内容
    fls -f ntfs -d image.dd            # 仅列出已删除文件
$LogFile 与 $UsnJrnl
  • $LogFile:NTFS 事务日志,记录元数据变更,可恢复近期修改
  • $UsnJrnl:USN 变更日志,记录文件创建/删除/重命名等操作
  • 提取工具:MFTECmd、NTFS Log Tracker
Alternate Data Streams (ADS)
  • NTFS 支持在文件上附加多个数据流,常用于隐藏数据
    bash
    # 查看 ADS
    streams <file>
    # Sleuth Kit 方式
    fls -r -f ntfs image.dd | grep ":"
时间戳 (MACB)
  • M (Modified):文件内容最后修改时间
  • A (Accessed):文件最后访问时间
  • C (Created/MFT Changed):MFT 记录最后变更时间
  • B (Born):文件创建时间(仅 $STANDARD_INFORMATION 有)
  • $FILE_NAME 和 $STANDARD_INFORMATION 可能有不同的时间戳,注意对比

FAT 文件系统

关键结构
  • FAT 表:记录簇链,0x0FFFFFFF 标记文件结束
  • 目录项:32 字节,含文件名、起始簇、大小、时间
  • 长文件名 (LFN):连续多个 32 字节目录项存储 Unicode 文件名
已删除文件恢复
  • 删除时首字节改为 0xE5,簇链清零,但数据区未擦除
  • 恢复方法:
    bash
    fls -f fat -d image.dd           # 列出已删除文件
    icat -f fat image.dd <簇号>      # 提取内容
    # 或使用 testdisk / photorec

ext4 文件系统

关键概念
  • inode:存储文件元数据(权限、时间、块指针)
  • 块组:文件系统划分为多个块组,每组有自己的超级块备份
  • 日志 (Journal):JBD2 日志记录元数据操作,journalctl 或直接解析
已删除文件恢复
  • ext4 默认开启 dir_index,删除后 inode 标记清零
  • 使用 extundelete 或 ext4magic 恢复
    bash
    extundelete --restore-all /dev/sdX1
    ext4magic image.dd -f /path/to/deleted/file -d output/
时间戳分析
  • istat -f ext4 image.dd <inode号> 查看 atime/mtime/ctime/ctime
  • debugfs 进入交互式调试模式:
    bash
    debugfs image.dd
    debugfs: ls -l /path/to/dir
    debugfs: stat <inode>

Windows 事件日志

常见日志位置
  • 系统事件:C:\Windows\System32\winevt\Logs\System.evtx
  • 安全事件:C:\Windows\System32\winevt\Logs\Security.evtx
  • 应用事件:C:\Windows\System32\winevt\Logs\Application.evtx
  • PowerShell 日志:Microsoft-Windows-PowerShell%4Operational.evtx
  • RDP 登录:Microsoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx
关键事件 ID
ID来源含义
4624Security登录成功
4625Security登录失败
4634Security注销
4688Security新进程创建
4720Security账户创建
7045System服务安装
1102Security日志清除
解析工具
bash
# Python 解析
python3 -c "
import Evtx.Evtx as evtx
with evtx.Evtx('Security.evtx') as log:
    for record in log.records():
        print(record.xml())
"
# 命令行工具
wevtx_dump Security.evtx
chainsaw hunt Security.evtx --mapping sigma

浏览器痕迹

Chrome/Edge (Chromium)
  • 历史记录:%LOCALAPPDATA%\Google\Chrome\User Data\Default\History(SQLite)
  • 下载记录:同上文件的 downloads 表
  • Cookie:%LOCALAPPDATA%\Google\Chrome\User Data\Default\Cookies
  • 缓存:%LOCALAPPDATA%\Google\Chrome\User Data\Default\Cache\
Firefox
  • 历史记录:%APPDATA%\Mozilla\Firefox\Profiles\<profile>\places.sqlite
  • 下载记录:downloads.sqlite(旧版)或 places.sqlite
  • Cookie:cookies.sqlite
查询示例
sql
-- Chrome 历史记录
SELECT datetime(last_visit_time/1000000-11644473600,'unixepoch','localtime'),
       url, title, visit_count
FROM urls ORDER BY last_visit_time DESC;

-- Chrome 下载记录
SELECT datetime(start_time/1000000-11644473600,'unixepoch','localtime'),
       target_path, total_bytes, state
FROM downloads ORDER BY start_time DESC;

常用工具速查

bash
# Sleuth Kit 命令行
fls -r -m / image.dd              # 列出文件(TSK 路径格式)
mactime -b body.txt -d            # 生成时间线
tsk_recover image.dd output/      # 批量恢复已删除文件
blkstat -f ntfs image.dd <簇号>   # 查看块分配状态
mmstat image.dd                   # 查看分区表

# Autopsy / FTK
# GUI 工具,适合综合分析

# 系统相关
reglookup NTUSER.DAT              # 注册表解析
regripper -r NTUSER.DAT -f ntuser # 注册表信息提取

© MuWinds, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/forensics-disk of MuWinds/BUUCTF_Agent.

Open the folder on GitHubat commit 95cc9e0

Compare with similar skills

Forensics Disk next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Forensics Disk compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Forensics Disk this skillMuWinds/BUUCTF_Agent267—~1kAutomated safety check: WarnApache-2.0
Fla Ascend Performancefla-org/flash-linear-attention5.8k—~6.3kAutomated safety check: PassMIT
Deepsec Documentation Guidevercel-labs/deepsec8.1k—~956Automated safety check: PassApache-2.0
Skill Scannergetsentry/skills1k4 repos~2.5kAutomated safety check: WarnApache-2.0
Serenity Aleabitoreddityan-labs/serenity-aleabitoreddit4801 repos~3.3kAutomated safety check: PassNone
Security Alert Triageelastic/agent-skills5921 repos~3.5kAutomated safety check: NotesApache-2.0

Similar skills

  • Fla Ascend Performance

    fla-org/flash-linear-attention

    Guidelines for Ascend NPU kernel / Triton-Ascend backend performance work in the FLA repo.

    5.8k GitHub stars~6.3k tokensUpdated today
    SecurityAuto-check passed
  • Deepsec Documentation Guide

    vercel-labs/deepsec

    Official

    Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.

    8.1k GitHub stars~956 tokensUpdated 8 days ago
    SecurityAuto-check passed
  • Skill Scanner

    getsentry/skills

    Official

    Scan agent skills for security issues. An agent skill from getsentry/skills.

    1k GitHub starsUsed in 4 repos~2.5k tokens
    SecurityAuto-check: warnings
  • Serenity Aleabitoreddit

    yan-labs/serenity-aleabitoreddit

    Apply trader Serenity's (@aleabitoreddit) AI/semiconductor supply-chain analytical lens to US-stock ideas and market judgment.

    480 GitHub starsUsed in 1 repo~3.3k tokens
    SecurityAuto-check passed
  • Security Alert Triage

    elastic/agent-skills

    Official

    Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge.

    592 GitHub starsUsed in 1 repo~3.5k tokens
    SecurityAuto-check: notes
  • Shiro Attack CLI

    SummerSec/ShiroAttack2

    当用户要求利用、检测或测试 Apache Shiro rememberMe 反序列化漏洞 (Shiro-550, CVE-2016-4437) 时使用。触发词包括 "Shiro"、"rememberMe"、"shiro attack"、"CVE-2016-4437"、"Shiro-550"、"爆破 Shiro key"、"利用 Shiro"、"Shiro…

    2.6k GitHub stars~945 tokensUpdated 4 mo ago
    SecurityAuto-check passed

More from MuWinds/BUUCTF_Agent

  • Misc

    MuWinds/BUUCTF_Agent

    杂项技术,包括隐写术、流量分析、编码转换、取证分析、AI 安全等非传统 CTF 分类. An agent skill from MuWinds/BUUCTF_Agent.

    267 GitHub stars~504 tokensUpdated 1 mo ago
    Auto-check passed
  • Web

    MuWinds/BUUCTF_Agent

    Web 安全攻防技术,包括 SQL 注入、XSS、文件上传、命令注入、SSRF、反序列化等常见漏洞的识别与利用. An agent skill from MuWinds/BUUCTF_Agent.

    267 GitHub stars~463 tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Forensics Disk

What does Forensics Disk do?

磁盘取证分析技术,涵盖 NTFS/FAT/ext 文件系统解析、文件恢复、时间线分析、日志挖掘等实战技能. An agent skill from MuWinds/BUUCTF_Agent. Forensics Disk is an agent skill from MuWinds/BUUCTF_Agent.

When should I use Forensics Disk?

Forensics Disk fits situations like: security work in your project.

How do I install Forensics Disk in Claude Code?

Run `npx skills add MuWinds/BUUCTF_Agent --skill forensics-disk -a claude-code`. Or copy the skill folder (skills/forensics-disk in MuWinds/BUUCTF_Agent) into .claude/skills/forensics-disk in your project. Claude Code loads it when a task matches its description.

How do I install Forensics Disk in Codex?

Run `npx skills add MuWinds/BUUCTF_Agent --skill forensics-disk -a codex`. Or copy the skill folder (skills/forensics-disk in MuWinds/BUUCTF_Agent) into .agents/skills/forensics-disk in your project. Codex loads it when a task matches its description.

Can I use Forensics Disk in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add MuWinds/BUUCTF_Agent --skill forensics-disk -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/forensics-disk, .gemini/skills/forensics-disk, .github/skills/forensics-disk and .opencode/skills/forensics-disk in your project.

What does Forensics Disk need to run?

Going by SKILL.md and its folder, Forensics Disk needs the command-line tools its instructions call (python3). Our summary lists: Python 3.

Does Forensics Disk access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Forensics Disk safe to install?

Our automated static check of SKILL.md flagged 2 warning(s): mentions a credentials file (ssh keys, cloud or package-manager tokens). Read the flagged lines before installing; the check is not a guarantee either way.

What licence does Forensics Disk use?

Forensics Disk is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Forensics Disk use?

About 1k tokens (SKILL.md is roughly 4.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Forensics Disk?

Skills that share tags, products or a category with Forensics Disk: Fla Ascend Performance (fla-org/flash-linear-attention, 5.8k stars), Deepsec Documentation Guide (vercel-labs/deepsec, 8.1k stars), Skill Scanner (getsentry/skills, 1k stars) and Serenity Aleabitoreddit (yan-labs/serenity-aleabitoreddit, 480 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Forensics Disk?

MuWinds (a GitHub user) maintains it in MuWinds/BUUCTF_Agent, which has 267 GitHub stars. The repository holds 3 skills in this directory. The repository was last updated on September 5, 2026.

Source: MuWinds/BUUCTF_Agent on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.