canvas-forensic

Generate structured Obsidian Canvas canvases for forensic investigations.

Updated Apr 20, 2026
One-click install
npx skills add https://github.com/DCx7C5/cybersecsuite --skill canvas-forensic
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: canvas-forensic
Source: https://github.com/DCx7C5/cybersecsuite/tree/main/.claude/skills/canvas-forensic
Command: npx skills add https://github.com/DCx7C5/cybersecsuite --skill canvas-forensic

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Visualize forensic investigations by generating structured Obsidian Canvas canvases to map relationships, timelines, and artifacts within a case.

Core Features & Use Cases

  • Forensic archetypes: attack-graph, ioc-map, incident-timeline, threat-actor, kill-chain.
  • Standard archetypes: flowchart, mind-map, dashboard, knowledge-graph, kanban, comparison.
  • Use cases: build evidence networks, track incident response steps, and present findings to stakeholders.

Quick Start

Invoke a canvas_create call with your chosen archetype and data to generate a new forensic canvas stored at data/vault/wiki/canvases/.

Frequently Asked Questions about canvas-forensic

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I visualize a forensic investigation using an Obsidian Canvas?

You visualize a forensic investigation by generating structured Obsidian Canvas canvases that map relationships, timelines, and artifacts. This approach organizes threat analysis and incident storytelling into structured visual formats.

What types of diagrams can I use for incident management and threat analysis?

For incident management and threat analysis, you can use forensic archetypes including attack-graph, ioc-map, incident-timeline, threat-actor, and kill-chain. Standard archetypes like flowchart, mind-map, dashboard, and knowledge-graph are also supported.

How do I create an evidence network canvas for my case data?

You create an evidence network by invoking a canvas creation workflow with your chosen archetype and case data. This generates a new forensic canvas stored directly within the data vault canvases directory.

Can I use this approach to track incident response steps?

Yes, you can track incident response steps by generating structured canvases. Using archetypes like incident-timeline and kanban helps map response actions and present findings to stakeholders visually.

Does generating these canvases require any specific external dependencies?

Generating these canvases requires no external dependencies. The archetype-driven visualization features render on-demand within the vault structure without needing additional components.

What is the best way to map kill-chain and threat-actor relationships?

The best way to map kill-chain and threat-actor relationships is using specialized forensic archetypes. These generate structured knowledge-graph and attack-graph canvases to visualize complex evidence networks.