tag

forensics

38 indexed skills · max 10 per page

skills (38)

analyzing-slack-space-and-file-system-artifacts

mukul975/Anthropic-Cybersecurity-Skills · analyzing-slack-space-and-file-system-artifacts

0

Examine file system slack space, MFT entries, USN journal, and alternate data streams to recover hidden data and reconstruct file activity on NTFS volumes.

analyzing-disk-image-with-autopsy

mukul975/Anthropic-Cybersecurity-Skills · analyzing-disk-image-with-autopsy

0

Perform comprehensive forensic analysis of disk images using Autopsy to recover files, examine artifacts, and build investigation timelines.

extracting-browser-history-artifacts

mukul975/Anthropic-Cybersecurity-Skills · extracting-browser-history-artifacts

0

Extract and analyze browser history, cookies, cache, downloads, and bookmarks from Chrome, Firefox, and Edge for forensic evidence of user web activity.

performing-endpoint-forensics-investigation

mukul975/Anthropic-Cybersecurity-Skills · performing-endpoint-forensics-investigation

0

Performs digital forensics investigation on compromised endpoints including memory acquisition, disk imaging, artifact analysis, and timeline reconstruction. Use when investigating security incidents, collecting evidence for legal proceedings, or analyzing endpoint compromise scope. Activates for requests involving endpoint forensics, memory analysis, disk forensics, or incident investigation.

performing-cloud-log-forensics-with-athena

mukul975/Anthropic-Cybersecurity-Skills · performing-cloud-log-forensics-with-athena

0

Uses AWS Athena to query CloudTrail, VPC Flow Logs, S3 access logs, and ALB logs for forensic investigation. Covers CREATE TABLE DDL with partition projection, forensic SQL queries for detecting unauthorized access, data exfiltration, lateral movement, and privilege escalation. Use when investigating AWS security incidents or building cloud-native forensic workflows at scale.

analyzing-usb-device-connection-history

mukul975/Anthropic-Cybersecurity-Skills · analyzing-usb-device-connection-history

0

Investigate USB device connection history from Windows registry, event logs, and setupapi logs to track removable media usage and potential data exfiltration.

analyzing-prefetch-files-for-execution-history

mukul975/Anthropic-Cybersecurity-Skills · analyzing-prefetch-files-for-execution-history

0

Parse Windows Prefetch files to determine program execution history including run counts, timestamps, and referenced files for forensic investigation.

analyzing-linux-system-artifacts

mukul975/Anthropic-Cybersecurity-Skills · analyzing-linux-system-artifacts

0

Examine Linux system artifacts including auth logs, cron jobs, shell history, and system configuration to uncover evidence of compromise or unauthorized activity.

performing-mobile-device-forensics-with-cellebrite

mukul975/Anthropic-Cybersecurity-Skills · performing-mobile-device-forensics-with-cellebrite

0

Acquire and analyze mobile device data using Cellebrite UFED and open-source tools to extract communications, location data, and application artifacts.

analyzing-powershell-empire-artifacts

mukul975/Anthropic-Cybersecurity-Skills · analyzing-powershell-empire-artifacts

0

Detect PowerShell Empire framework artifacts in Windows event logs by identifying Base64 encoded launcher patterns, default user agents, staging URL structures, stager IOCs, and known Empire module signatures in Script Block Logging events.

prevpage 1 / 4next