0xbigbadjon avatar

0xbigbadjon

Community

@rjonhaas

1Followers
|
5Public Repos
|
17Published Skills

Agent Skills by 0xbigbadjon

Showing 17 vetted skills indexed across 1 GitHub repositories.

rjonhaasrjonhaas
1

Investigation Report Generation

Generate evidence-backed DFIR investigation reports from triage outputs and COP.

Community
Advanced
rjonhaasrjonhaas
1

Daedalus — Adaptive Artifact Handler

Detects forensic artifact classes and maps them to SIFTics phase scripts.

Community
Advanced
rjonhaasrjonhaas
1

File System & Carving (The Sleuth Kit / EWF Tools)

Verify, mount read-only, enumerate filesystems, and carve artifacts from E01/EWF images with Sleuth Kit and EWF tools.

Community
Intermediate
rjonhaasrjonhaas
1

Timeline Generation (Plaso / log2timeline)

Generate correlated super-timelines from digital evidence using log2timeline and Plaso.

Community
Intermediate
rjonhaasrjonhaas
1

Triage Methodology (Phase Sequencing & Decision Engine)

Orchestrate DFIR triage by sequencing evidence-analysis phases across disk, memory, network, and application artifacts.

Community
Advanced
rjonhaasrjonhaas
1

Cloud Forensics (AWS GuardDuty / CloudTrail / S3)

Analyze AWS GuardDuty and CloudTrail logs to reconstruct incident timelines.

Community
Intermediate
rjonhaasrjonhaas
1

Skill: Hypothesis Engine (Working-Theory Ledger)

Maintain an append-only JSONL ledger scoring investigative hypotheses against evolving evidence.

Community
Advanced
rjonhaasrjonhaas
1

EDR Telemetry & Live Hunt Collections

Analyze EDR exports and Velociraptor ZIPs to extract suspicious processes and persistence signals.

Community
Advanced
rjonhaasrjonhaas
1

Threat Hunting & IOC Sweeps (YARA / Velociraptor)

Scan file systems and memory images with YARA and endpoints via Velociraptor hunts.

Community
Intermediate
rjonhaasrjonhaas
1

Skill: CVE Attribution (Intel ICS)

Cross-reference investigation narratives and COP data to attribute CVEs.

Community
Advanced
rjonhaasrjonhaas
1

Investigation Section Chief (DFIR — NIMS ICS Role)

Orchestrate DFIR investigations with authority-gated decisions and Common Operating Picture updates.

Community
Advanced
rjonhaasrjonhaas
1

Windows Artifacts (EZ Tools / Autoruns / Event Logs)

Parse Windows forensic artifacts into CSV outputs for DFIR triage.

Community
Advanced
rjonhaasrjonhaas
1

Skill: Malware Analysis (Static / Capability)

Extract static evidence and map malware capabilities to ATT&CK techniques.

Community
Advanced
rjonhaasrjonhaas
1

Memory Forensics (Volatility 3 / Memory Baseliner)

Analyze Windows memory images with Volatility 3 to detect hidden processes and anomalies.

Community
Advanced
rjonhaasrjonhaas
1

Network Analysis (PCAP / Zeek / Netflow)

Analyze PCAP, Zeek logs, and netflow records for suspicious network behavior.

Community
Advanced
rjonhaasrjonhaas
1

Linux Host Forensics

Correlate Linux user, authentication, persistence, and execution artifacts for compromise indicators.

Community
Advanced
rjonhaasrjonhaas
1

macOS Triage Analysis — SIFT Workstation Runbook

Triage macOS artifact collections with mac_apt and Unified Logs.

Community
Advanced