digital-forensics-analyst

Identify and preserve forensic artifacts with chain-of-custody documentation.

7|1|Updated May 19, 2026
One-click install
npx skills add https://github.com/daemon-blockint-tech/Agentic-Enteprises-Skill --skill digital-forensics-analyst
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: digital-forensics-analyst
Source: https://github.com/daemon-blockint-tech/Agentic-Enteprises-Skill/tree/main/digital-forensics-analyst
Command: npx skills add https://github.com/daemon-blockint-tech/Agentic-Enteprises-Skill --skill digital-forensics-analyst

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

Guides security teams through the complete lifecycle of digital-forensics investigations: evidence acquisition planning, chain-of-custody documentation, artifact analysis, timeline correlation, and professional reporting for IR, legal, and counsel.

Core Features & Use Cases

  • Evidence acquisition planning and custody management across host, disk, memory, mobile, and cloud artifacts
  • Artifact analysis guidance for OS, network, logs, and cloud services with source citations
  • UTC-normalized super-timeline construction and report-ready packaging
  • Malware artifact triage workflow and expert-witness prep material
  • IR, insurance, and counsel-facing outputs including executive summaries and appendices

Quick Start

Draft an evidence collection plan for a suspected incident using the standard chain-of-custody workflow outlined in this skill.

Frequently Asked Questions about digital-forensics-analyst

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I maintain chain of custody during a digital forensics investigation?

Chain of custody is maintained by applying structured documentation workflows for evidence provenance, time-stamped logs, and custody records, ensuring artifact integrity across host, disk, memory, mobile, and cloud sources for legal reporting.

What is the best way to build a super-timeline for incident response forensics?

Building a super-timeline involves correlating UTC-normalized forensic artifacts from OS, network, and cloud logs into a structured chronological sequence, enabling precise timeline reconstruction for incident investigation and expert-witness-ready reporting.

How do I create an evidence collection plan for cloud and mobile artifacts?

Evidence collection planning requires identifying and preserving forensic artifacts across mobile and cloud sources, enforcing custody and provenance requirements while structuring acquisition workflows for incident response and legal compliance contexts.

Does this digital forensics workflow support expert-witness-ready documentation?

Yes, the workflow generates counsel-facing outputs including executive summaries, appendices, and professional reports with source citations, specifically designed to meet expert-witness reporting and legal compliance documentation requirements.

When do I need a malware artifact triage workflow during an investigation?

Malware artifact triage is needed during incident response to quickly identify and preserve malicious forensic artifacts, applying analysis guidance for OS and network sources while maintaining strict chain-of-custody documentation.

Can I use this for incident response evidence acquisition across multiple platforms?

Yes, evidence acquisition planning and custody management cover host, disk, memory, mobile, and cloud artifacts, applying structured workflows to preserve evidence integrity for IR, legal, and insurance-facing outputs.