Topic · Security

Best digital forensics skills for Claude Code, Codex and other agents.

Skills that investigate incidents and collect forensic evidence.
skills
88
official
1

Digital forensics skills, ranked

Ranked by score. Sort bymost stars,trending,newest,recently updated

Digital forensics skills, ranked
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
1

Provides malware analysis and network traffic techniques for CTF challenges.

ljagiello/ctf-skills3.4k1 repo~2.1kAutomated safety check: NotesMIT24 days ago
2

Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

mukul975/Anthropic-Cybersecurity-Skills34k—~2.3kAutomated safety check: PassApache-2.01 mo ago
3

Supply chain investigation, evidence recovery, and forensic analysis for GitHub repositories.

Tommy-yw/RunbookHermes5463 repos~5kAutomated safety check: PassMIT4 mo ago
4

Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

mukul975/Anthropic-Cybersecurity-Skills34k—~2.8kAutomated safety check: PassApache-2.01 mo ago
5

Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

mukul975/Anthropic-Cybersecurity-Skills34k—~1.2kAutomated safety check: PassApache-2.01 mo ago
6

A skill your agent uses when asked to investigate Conditional Access policy changes, sign-in failures related to CA policies (error codes 53000, 50074, 530032), or suspected policy…

SCStelz/security-investigator249—~3.8kAutomated safety check: PassMIT2 days ago
7

Digital forensics and incident response - Windows event log analysis, PCAP forensics, filesystem artifact analysis, AD attack detection, and timeline correlation.

transilienceai/communitytools562—~1.5kAutomated safety check: PassMIT2 mo ago
8
8.CoreOfficial

Status-first routing, bounded evidence collection, and safety guidance for issue-graph.

vercel-labs/issue-graph125—~2.6kAutomated safety check: PassApache-2.07 days ago
9

Guides authorized packet capture and analysis with TShark, Wireshark's command-line tool, for security investigations, malware detection and forensic examination of network traffic.

AgentSecOps/SecOpsAgentKit2201 repo~4.8kAutomated safety check: NotesUnknown5 mo ago
10

Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

mukul975/Anthropic-Cybersecurity-Skills34k—~2.7kAutomated safety check: PassApache-2.01 mo ago
11

Captures an analyzable sample from a live system when the target leaves no file on disk, by finding abnormal executable memory and the execution context that reached it.

dslsdzc/rev-skills125—~2kAutomated safety check: PassApache-2.03 days ago
12

Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

mukul975/Anthropic-Cybersecurity-Skills34k—~2kAutomated safety check: PassApache-2.01 mo ago
13

Systematic debugging with Iron Law methodology. An agent skill from catlog22/Claude-Code-Workflow.

catlog22/Claude-Code-Workflow2.1k—~1.1kAutomated safety check: NotesMIT3 mo ago
14

A skill your agent uses for authorized digital forensics including memory dumps, disk timelines, PCAP investigation, artifact triage, and IR evidence preservation.

zhaoxuya520/reverse-skill40k2 repos~389Automated safety check: WarnMIT16 days ago
15

Reconstructs folder browsing history from Windows Shellbag registry data using SBECmd and Shellbags Explorer, even for folders that were later deleted.

mukul975/Anthropic-Cybersecurity-Skills34k—~2.3kAutomated safety check: PassApache-2.01 mo ago
16

Amazon brand protection toolkit. An agent skill from nexscope-ai/eCommerce-Skills.

nexscope-ai/eCommerce-Skills1.1k—~770Automated safety check: PassMIT1 mo ago
17

Black box flight recorder for the server. An agent skill from bolivian-peru/os-moda.

bolivian-peru/os-moda119—~624Automated safety check: PassApache-2.03 mo ago
18

A skill your agent uses when responding to or forensically investigating an incident — triage acquisition (Velociraptor/KAPE), Volatility 3 memory forensics, Chainsaw/Hayabusa EVTX timelining…

hypnguyen1209/offensive-claude386—~2.5kAutomated safety check: PassMIT10 days ago
19

Diagnostics-only BGP troubleshooting patterns for neighbor state, route exchange, prefix policy, AS path inspection, and safe evidence collection.

affaan-m/ECC275k1 repo~1.4kAutomated safety check: PassMIT3 days ago
20

Provides digital forensics and signal analysis techniques for CTF challenges.

ljagiello/ctf-skills3.4k—~9.2kAutomated safety check: WarnMIT24 days ago
21

A skill your agent uses when asked to trace authentication flows, analyze SessionId chains, investigate token reuse vs interactive MFA, or assess geographic anomalies in sign-ins.

SCStelz/security-investigator249—~8.6kAutomated safety check: PassMIT2 days ago
22

Debug complex issues using competing hypotheses with parallel investigation, evidence collection, and root cause arbitration.

wshobson/agents40k1 repo~1.2kAutomated safety check: PassMIT3 days ago
23

Analyze disk images, file systems, and memory captures for digital evidence recovery in forensic investigations and CTF challenges.

briiirussell/cybersecurity-skills413—~1.5kAutomated safety check: NotesMIT4 mo ago
24

Judge product usability and evidence quality. An agent skill from aryaniyaps/lamina.

aryaniyaps/lamina115—~432Automated safety check: PassApache-2.07 days ago
25

Build collaborative forensic incident timelines using Timesketch to ingest, normalize, and analyze multi-source event data (including Plaso output) for attack chain reconstruction and investigation…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.4kAutomated safety check: NotesApache-2.01 mo ago
26

SQL-powered forensic investigation and system interrogation using osquery to query operating systems as relational databases.

AgentSecOps/SecOpsAgentKit2201 repo~4.9kAutomated safety check: NotesUnknown5 mo ago
27

Endpoint visibility, digital forensics, and incident response using Velociraptor Query Language (VQL) for evidence collection and threat hunting at scale.

AgentSecOps/SecOpsAgentKit2201 repo~3.1kAutomated safety check: PassUnknown5 mo ago
28

Performs digital forensics investigation on compromised endpoints including memory acquisition, disk imaging, artifact analysis, and timeline reconstruction.

mukul975/Anthropic-Cybersecurity-Skills34k—~2kAutomated safety check: NotesApache-2.01 mo ago
29

Perform forensic analysis of network packet captures (PCAP/PCAPNG) using Wireshark, tshark, and tcpdump to reconstruct network communications, extract transferred files, identify malicious traffic…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.3kAutomated safety check: PassApache-2.01 mo ago
30

Automates SOC 2 Type II audit preparation including gap assessment against AICPA Trust Services Criteria (CC1-CC9), evidence collection from cloud providers and identity systems, control testing…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.7kAutomated safety check: PassApache-2.01 mo ago
31

Authorized digital forensics: memory dumps, disk timelines, PCAP investigation, artifact triage, and incident-response evidence preservation.

sickn33/agentic-awesome-skills47k1 repo~495Automated safety check: PassMITyesterday
32

Perform comprehensive forensic analysis of raw (dd), E01, or AFF disk images with Autopsy and The Sleuth Kit, recovering deleted files, examining metadata and embedded artifacts, keyword searching…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.7kAutomated safety check: NotesApache-2.01 mo ago
33

Performs Linux memory acquisition using LiME (Linux Memory Extractor) kernel module and analysis with Volatility 3 framework.

mukul975/Anthropic-Cybersecurity-Skills34k—~631Automated safety check: PassApache-2.01 mo ago
34

Parse Microsoft Outlook PST and OST files using libpff and pst-utils to extract message content, headers, attachments, deleted items, and MAPI metadata, including recovery of items from the…

mukul975/Anthropic-Cybersecurity-Skills34k—~3.2kAutomated safety check: PassApache-2.01 mo ago
35

Parses the Windows Amcache.hve registry hive with Eric Zimmerman's AmcacheParser and Timeline Explorer to extract evidence of program execution, application installation, and driver loading…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.8kAutomated safety check: PassApache-2.01 mo ago
36

Analyzes Windows Security, System, and Sysmon event logs in Splunk to detect authentication attacks, privilege escalation, persistence mechanisms, and lateral movement using SPL queries mapped to…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.8kAutomated safety check: PassApache-2.01 mo ago
37

Parse Windows LNK shortcut files to extract target paths, MAC timestamps, volume serial numbers, and machine identifiers for forensic timeline reconstruction.

mukul975/Anthropic-Cybersecurity-Skills34k—~3.2kAutomated safety check: PassApache-2.01 mo ago
38

Extract and analyze Windows Registry hives with tools like RegRipper and Registry Explorer to uncover user activity, installed software, autostart/persistence entries, and evidence of system…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.9kAutomated safety check: PassApache-2.01 mo ago
39

Generate forensic super-timelines with Plaso's log2timeline.py, pinfo.py, psort.py, and psteal.py CLI tools (fusing file-system MACB, registry, EVTX, browser history, prefetch, LNK, and more), then…

mukul975/Anthropic-Cybersecurity-Skills34k—~1.9kAutomated safety check: NotesApache-2.01 mo ago
40

Detects rootkit presence on compromised systems by identifying hidden processes, hooked system calls, modified kernel structures, and covert network connections using Volatility memory forensics…

mukul975/Anthropic-Cybersecurity-Skills34k—~3kAutomated safety check: PassApache-2.01 mo ago
41

Extracts cached credentials, password hashes, Kerberos tickets, and authentication tokens from Windows memory dumps using Volatility 3, Mimikatz, and pypykatz.

mukul975/Anthropic-Cybersecurity-Skills34k—~3.4kAutomated safety check: PassApache-2.01 mo ago
42

Collect and analyze cloud forensic evidence using AWS CLI, Azure CLI, or gcloud to snapshot volumes, capture instance metadata and security group configurations, and preserve cloud-native logs…

mukul975/Anthropic-Cybersecurity-Skills34k—~3.4kAutomated safety check: NotesApache-2.01 mo ago
43

Investigate AWS account compromise by querying CloudTrail with boto3's LookupEvents or AWS Athena SQL over S3-delivered logs, filtering on suspicious user agents, source IPs, and event names to…

mukul975/Anthropic-Cybersecurity-Skills34k—~845Automated safety check: PassApache-2.01 mo ago
44

Uses AWS Athena to query CloudTrail, VPC Flow Logs, S3 access logs, and ALB logs for forensic investigation.

mukul975/Anthropic-Cybersecurity-Skills34k—~3.7kAutomated safety check: PassApache-2.01 mo ago
45

Conduct disk forensics investigations using forensic imaging, file system analysis, and timeline reconstruction, with tools such as FTK Imager, Autopsy, and The Sleuth Kit, for evidence acquisition…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.7kAutomated safety check: PassApache-2.01 mo ago
46

Investigates insider threat incidents involving employees, contractors, or trusted partners who misuse authorized access to steal data, sabotage systems, or violate security policies, combining…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.9kAutomated safety check: PassApache-2.01 mo ago
47

Executes a structured ransomware incident response from detection through containment, forensic analysis, decryption assessment, recovery, and post-incident hardening, covering ransom negotiation…

mukul975/Anthropic-Cybersecurity-Skills34k—~2.9kAutomated safety check: PassApache-2.01 mo ago
48

A skill your agent uses when a security incident has been detected or declared and needs classification, triage, escalation path determination, and forensic evidence collection.

alirezarezvani/claude-skills28k—~3.8kAutomated safety check: PassMIT1 mo ago

Questions, answered from the data.

What is the best digital forensics skill?

Ctf Malware from ljagiello/ctf-skills ranks first of the 88 digital forensics skills listed here, with the highest score: its repository has 3.4k GitHub stars, 1 other GitHub owner carry a copy, its SKILL.md loads about 2.1k tokens and it has informational notes only in the automated safety check. Next come Campaign Attribution Evidence Analysis and Oss Forensics.

Which digital forensics skills are official?

1 of the 88 digital forensics skills are official, published by the vendor's own GitHub organization: Core.

How are these skills ranked?

By Skill Navigator score, which combines the GitHub stars of the skill's repository (shared across that repo's skills and discounted for large collections), how many other GitHub owners carry a copy of the skill, and automated SKILL.md quality checks, minus penalties for safety-check warnings and for each further skill from the same repository. Skills that fail the safety check are not listed.