Agent Skills by 0xbigbadjon
Showing 17 vetted skills indexed across 1 GitHub repositories.
Investigation Report Generation
Generate evidence-backed DFIR investigation reports from triage outputs and COP.
Daedalus — Adaptive Artifact Handler
Detects forensic artifact classes and maps them to SIFTics phase scripts.
File System & Carving (The Sleuth Kit / EWF Tools)
Verify, mount read-only, enumerate filesystems, and carve artifacts from E01/EWF images with Sleuth Kit and EWF tools.
Timeline Generation (Plaso / log2timeline)
Generate correlated super-timelines from digital evidence using log2timeline and Plaso.
Triage Methodology (Phase Sequencing & Decision Engine)
Orchestrate DFIR triage by sequencing evidence-analysis phases across disk, memory, network, and application artifacts.
Cloud Forensics (AWS GuardDuty / CloudTrail / S3)
Analyze AWS GuardDuty and CloudTrail logs to reconstruct incident timelines.
Skill: Hypothesis Engine (Working-Theory Ledger)
Maintain an append-only JSONL ledger scoring investigative hypotheses against evolving evidence.
EDR Telemetry & Live Hunt Collections
Analyze EDR exports and Velociraptor ZIPs to extract suspicious processes and persistence signals.
Threat Hunting & IOC Sweeps (YARA / Velociraptor)
Scan file systems and memory images with YARA and endpoints via Velociraptor hunts.
Skill: CVE Attribution (Intel ICS)
Cross-reference investigation narratives and COP data to attribute CVEs.
Investigation Section Chief (DFIR — NIMS ICS Role)
Orchestrate DFIR investigations with authority-gated decisions and Common Operating Picture updates.
Windows Artifacts (EZ Tools / Autoruns / Event Logs)
Parse Windows forensic artifacts into CSV outputs for DFIR triage.
Skill: Malware Analysis (Static / Capability)
Extract static evidence and map malware capabilities to ATT&CK techniques.
Memory Forensics (Volatility 3 / Memory Baseliner)
Analyze Windows memory images with Volatility 3 to detect hidden processes and anomalies.
Network Analysis (PCAP / Zeek / Netflow)
Analyze PCAP, Zeek logs, and netflow records for suspicious network behavior.
Linux Host Forensics
Correlate Linux user, authentication, persistence, and execution artifacts for compromise indicators.
macOS Triage Analysis — SIFT Workstation Runbook
Triage macOS artifact collections with mac_apt and Unified Logs.