artifact-collector

Collect forensic artifacts from endpoints via D&R rules.

Updated Nov 5, 2025
One-click install
npx skills add https://github.com/tekgrunt/boot-test --skill artifact-collector
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: artifact-collector
Source: https://github.com/tekgrunt/boot-test/tree/main/.claude-plugin/plugins/limacharlie-skills/skills/artifact-collector
Command: npx skills add https://github.com/tekgrunt/boot-test --skill artifact-collector

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Artifact collection is critical for incident response, forensic analysis, and compliance, and this skill centralizes and streamlines gathering evidence from endpoints.

Core Features & Use Cases

  • Collect files, memory dumps, Windows Event Logs, Mac Unified Logs, and PCAP data
  • Support manual collection, automated rules, and offline collection via Reliable Tasking
  • Typical use cases include malware analysis, timeline creation, and investigations across on-prem and cloud environments

Quick Start

Hash a suspicious file to verify integrity, then collect it along with related artifacts to preserve evidence for the investigation.

Frequently Asked Questions about artifact-collector

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I collect forensic artifacts from endpoints during an incident response?

Forensic artifact collection involves gathering files, memory dumps, Windows Event Logs, Mac Unified Logs, and PCAP data to preserve endpoint evidence for investigations. This skill centralizes gathering evidence across incident response, forensic analysis, and compliance workflows.

Can I automate forensic artifact collection across offline endpoints?

Yes, automated and offline forensic artifact collection is supported using D&R rules and Reliable Tasking. This ensures endpoint evidence is gathered continuously even when systems are offline, preserving critical data for incident response and compliance investigations.

What types of logs and memory data can I gather for forensic timeline creation?

For forensic timeline creation, you can gather memory dumps, Windows Event Logs, Mac Unified Logs, and PCAP data. Collecting these specific artifacts helps analyze malware behavior and reconstruct incident timelines across on-prem and cloud environments.

Do I need specific extensions to collect PCAP data and memory dumps from endpoints?

Yes, collecting PCAP data and memory dumps requires the Artifact extension and Reliable Tasking. These components enable automated, offline, and real-time collection of forensic evidence across endpoints via D&R rules.

What is the best way to preserve suspicious files for forensic investigations?

The best way to preserve suspicious files for forensic investigations is to hash the file to verify integrity, then collect it along with related artifacts. This preserves evidence for malware analysis and incident response workflows.