Topic · Security
Best digital forensics skills, page 2
Digital forensics skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 49 | Analyze memory dumps using Volatility3 plugins to detect injected code, rootkits, credential theft, and malware artifacts in Windows, Linux, and macOS memory images. | mukul975/ | 34k | — | ~2.1k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 50 | Performs comprehensive Windows forensic artifact analysis using Eric Zimmerman's open-source EZ Tools suite (KAPE, MFTECmd, PECmd, LECmd, JLECmd, Timeline Explorer) to parse registry hives, prefetch… | mukul975/ | 34k | — | ~3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 51 | Analyze Linux, SteamOS, Steam Deck, Wine, or Proton game-security boundaries. | gmh5225/ | 3.6k | — | ~220 | Automated safety check: Pass | MIT | yesterday |
| 52 | Analyzes RAM memory dumps from compromised systems using the Volatility framework to identify malicious processes, injected code, network connections, loaded modules, and extracted credentials. | mukul975/ | 34k | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 53 | Use Scapy to craft, send, sniff, and dissect TCP/UDP/ICMP/DNS packets, analyze pcap files, implement SYN scans, and detect anomalous traffic such as fragmented or malformed packets. | mukul975/ | 34k | — | ~626 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 54 | Examine NTFS slack space, MFT entries, the USN Change Journal, and Alternate Data Streams (ADS) to recover hidden or residual data, reconstruct deleted-file metadata, and reconstruct available… | mukul975/ | 34k | — | ~3.7k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 55 | Performs memory forensics analysis using Volatility 3 to extract evidence of malware execution, process injection, network connections, and credential theft from RAM dumps captured during incident… | mukul975/ | 34k | — | ~2.6k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 56 | Detects and analyzes process injection techniques used by malware including classic DLL injection, process hollowing, APC injection, thread hijacking, and reflective loading. | mukul975/ | 34k | — | ~3.5k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 57 | Uses Rekall memory forensics framework to analyze memory dumps for process hollowing, injected code via VAD anomalies, hidden processes, and rootkit detection. | mukul975/ | 34k | — | ~642 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 58 | Run Hayabusa against collected Windows EVTX files to apply Sigma detection rules and produce a prioritized, chronological CSV/JSON timeline with severity levels, MITRE ATT&CK mappings, and… | mukul975/ | 34k | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 59 | Parse Windows forensic artifacts—$MFT/$J (MFTECmd), Prefetch (PECmd), registry hives (RECmd), shellbags, and Amcache—into normalized CSV/JSON with Eric Zimmerman's EZ Tools, then load results into… | mukul975/ | 34k | — | ~2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 60 | Recovers files from disk images and unallocated space using Foremost's header-footer signature carving, extracting evidence independent of the file system's state. | mukul975/ | 34k | — | ~3.1k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 61 | Analyze volatile memory (RAM) dumps using the Volatility 3 framework to extract running processes, network connections, loaded modules, credentials, and encryption keys, and to detect process… | mukul975/ | 34k | — | ~3k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 62 | Forensic bug and issue triage. An agent skill from aj-geddes/claude-code-bmad-skills. | aj-geddes/ | 487 | — | ~2.8k | Automated safety check: Pass | Unknown | 3 mo ago |
| 63 | Implement and maintain compliance with SOC 2, HIPAA, PCI-DSS, and GDPR using unified control mapping, policy-as-code enforcement, and automated evidence collection. | ancoleman/ | 526 | — | ~4k | Automated safety check: Pass | MIT | 10 mo ago |
| 64 | Performs forensic analysis of SQLite databases by examining B-tree page structures, recovering deleted records from freelist pages and Write-Ahead Log (WAL) files, decoding encoded timestamps, and… | mukul975/ | 34k | — | ~3.6k | Automated safety check: Warn | Apache-2.0 | 1 mo ago |
| 65 | Extracts and analyzes browser history, cookies, cache, downloads, and bookmarks from Chrome, Firefox, and Edge using sqlite3, DB Browser for SQLite, Hindsight, and NirSoft tools… | mukul975/ | 34k | — | ~2.9k | Automated safety check: Warn | Apache-2.0 | 1 mo ago |
| 66 | Audit a Node.js project's installed npm dependency tree for known CVEs by wrapping the npm audit JSON output and emitting findings in the canonical penetration-tester schema. | jeremylongshore/ | 2.8k | — | ~2.5k | Automated safety check: Notes | MIT | today |
| 67 | Audit a Python project's installed dependencies for known CVEs by wrapping pip-audit (PyPA's official vulnerability auditor) and emitting findings in the canonical penetration-tester schema. | jeremylongshore/ | 2.8k | — | ~2.3k | Automated safety check: Notes | MIT | today |
| 68 | Memory forensics playbook using Volatility 2/3. An agent skill from yaklang/hack-skills. | yaklang/ | 2.4k | — | ~2.5k | Automated safety check: Pass | MIT | 25 days ago |
| 69 | Coordinate Levyra work through OpenClaw using a dedicated repository workspace, compact delegation, specialized review and CI agents, project-native skills, evidence collection, durable memory, and… | LUC4N3X/ | 531 | — | ~2.2k | Automated safety check: Pass | GPL-3.0 | today |
| 70 | Guides forensic analysis of disk images — integrity verification, partition layout, file-system survey, deleted-file recovery and timeline reconstruction. | criptogus/ | 288 | — | ~919 | Automated safety check: Pass | CC-BY-SA-4.0 | 29 days ago |
| 71 | Systematically map and remove malware, backdoors, and attacker persistence mechanisms (registry Run keys, scheduled tasks, WMI subscriptions, services, cron/init.d) from infected Windows and Linux… | mukul975/ | 34k | — | ~2.2k | Automated safety check: Warn | Apache-2.0 | 1 mo ago |
| 72 | GEO-focused fact-checking and evidence collection assistant for written content. | LeoYeAI/ | 2.2k | — | ~5.3k | Automated safety check: Pass | MIT | 2 mo ago |
| 73 | 73.Forensics Build a read-only compromise timeline and evidence bundle from local Git history and public forge/archive records. | alpha-omega-security/ | 231 | — | ~2.1k | Automated safety check: Notes | MIT | yesterday |
| 74 | Compliance and security auditing for Cursor IDE usage: SOC 2, GDPR, HIPAA assessment, evidence collection, and remediation. | jeremylongshore/ | 2.8k | — | ~2.3k | Automated safety check: Notes | MIT | today |
| 75 | 75.Log Evasion 日志分析与日志逃逸方法论。理解蓝队如何通过日志追踪攻击行为(SIEM/Event Log/Syslog),以及红队如何规避日志记录或精准清除痕迹。当需要设计无痕操作或分析日志监控覆盖范围时使用 | wgpsec/ | 1.8k | — | ~1.2k | Automated safety check: Pass | No licence | 5 days ago |
| 76 | 内存取证与反内存取证方法论。从蓝队视角理解内存取证如何发现恶意行为(Volatility3 分析流程),从红队视角掌握如何规避内存检测(进程隐藏、内存加密、痕迹清除)。当需要分析内存 dump 或设计反取证策略时使用 | wgpsec/ | 1.8k | — | ~975 | Automated safety check: Notes | No licence | 5 days ago |
| 77 | Design a focused lesson observation protocol with specific look-fors and evidence collection methods. | GarethManning/ | 835 | — | ~5k | Automated safety check: Pass | Unknown | 1 mo ago |
| 78 | Guides continuous privacy compliance monitoring implementation including automated control testing, evidence collection automation, real-time compliance dashboards, alert-based remediation… | mukul975/ | 295 | — | ~4.8k | Automated safety check: Pass | Apache-2.0 | 6 mo ago |
| 79 | Build a reproducible Google Search workflow that validates parameters, optional result sections, and bounded pagination. | jeremylongshore/ | 2.8k | — | ~1.1k | Automated safety check: Pass | MIT | today |
| 80 | 移动设备取证:Android/iOS 备份解析、应用数据提取、删除恢复与时间线. An agent skill from dslsdzc/rev-skills. | dslsdzc/ | 125 | — | ~1.6k | Automated safety check: Pass | Apache-2.0 | 3 days ago |
| 81 | AWS VPC networking audit covering CIDR architecture, Security Group and NACL rule analysis, Transit Gateway connectivity, VPC Flow Log forensics, Route Table validation, and ENI/EIP resource… | LeoYeAI/ | 2.2k | — | ~4.5k | Automated safety check: Pass | Apache-2.0 | 2 mo ago |
| 82 | Incident response process management following the NIST 800-61 lifecycle. | LeoYeAI/ | 2.2k | — | ~5k | Automated safety check: Pass | Apache-2.0 | 2 mo ago |
| 83 | Network forensics evidence collection and analysis during security incidents. | LeoYeAI/ | 2.2k | — | ~5k | Automated safety check: Pass | Apache-2.0 | 2 mo ago |
| 84 | Run digital forensics and incident response — triage, evidence acquisition with chain of custody, host and cloud artifact analysis, timeline reconstruction, scoping, containment, eradication, and… | trilwu/ | 156 | — | ~3.9k | Automated safety check: Notes | MIT | 1 mo ago |
| 85 | 磁盘/文件系统取证:删除恢复、时间线、可疑文件定位. An agent skill from dslsdzc/rev-skills. | dslsdzc/ | 125 | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | 3 days ago |
| 86 | Guides privacy audit evidence collection processes including evidence planning, sampling strategies, documentation standards, chain of custody, interview techniques, system walkthrough procedures… | mukul975/ | 295 | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | 6 mo ago |
| 87 | Conducts digital forensics investigations following a personal data breach, covering evidence preservation, chain of custody documentation, log analysis, scope determination, and root cause analysis. | mukul975/ | 295 | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | 6 mo ago |
| 88 | On-site and remote vendor audit procedures per GDPR Article 28(3)(h). | mukul975/ | 295 | — | ~2.6k | Automated safety check: Pass | Apache-2.0 | 6 mo ago |
Explore related skills
Category
More topics in Security
- Security review636
- Web application vulnerabilities467
- Vulnerability scanning304
- Static analysis and SAST283
- Security operations246
- Supply chain security233
- Threat modeling228
- Penetration testing182
- Cryptography159
- Prompt injection and agent security157
- Red teaming and adversary simulation148
- Reverse engineering and malware130
- OSINT119
- Secure coding113
- Cloud security95
- Smart contract auditing79
- Fuzzing76
- Bug bounty75
- Network security66
- Capture the flag45
- Mobile application security42
- Access reviews and audit trails38