forensic-analyst

Preserve evidence, reconstruct attack timelines, and generate auditable forensic reports using LimaCharlie.

Updated Nov 5, 2025
One-click install
npx skills add https://github.com/tekgrunt/boot-test --skill forensic-analyst
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: forensic-analyst
Source: https://github.com/tekgrunt/boot-test/tree/main/.claude-plugin/plugins/limacharlie-skills/skills/forensic-analyst
Command: npx skills add https://github.com/tekgrunt/boot-test --skill forensic-analyst

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Digital forensics investigations using LimaCharlie can be complex, time-consuming, and require coordinated data collection, timeline reconstruction, and defensible reporting. This skill provides a structured methodology and actionable workflows to guide analysts through evidence preservation, artifact analysis, and narrative development with auditable traceability.

Core Features & Use Cases

  • Guided, end-to-end 6-phase forensic workflow aligned with LimaCharlie capabilities (preservation, collection, examination, analysis, recording, reporting)
  • Comprehensive artifact coverage (memory, registry, logs, network, files) and timeline construction
  • Ready-to-use patterns for incident response, post-incident analysis, and proactive forensics in Windows and Linux environments
  • Real-world example: reconstruct an attack timeline from memory to final report using LCQL queries and artifact collection

Quick Start

Run a focused incident with memory and artifact collection using LimaCharlie LCQL queries to reconstruct the timeline and generate an evidence-backed report.

Frequently Asked Questions about forensic-analyst

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I reconstruct an attack timeline using LimaCharlie forensic artifacts?

Reconstruct an attack timeline by collecting and examining memory, registry, logs, and network artifacts using LimaCharlie LCQL queries. This forensic workflow correlates evidence across Windows and Linux endpoints to trace attacker activity from initial compromise to final actions.

What is the best way to preserve digital evidence and maintain chain-of-custody during incident response?

Preserve digital evidence and maintain chain-of-custody by following a structured 6-phase forensic workflow: preservation, collection, examination, analysis, recording, and reporting. This methodology enforces data integrity and generates auditable reports for defensible incident response investigations.

Can I perform memory analysis and artifact collection on both Windows and Linux endpoints?

Yes, memory analysis and artifact collection are fully supported across both Windows and Linux endpoints. The forensic workflow applies dedicated memory analysis tooling and LCQL queries to extract and examine volatile artifacts regardless of the endpoint operating system.

How do I generate auditable forensic reports from LCQL queries and collected evidence?

Generate auditable forensic reports by systematically recording findings from artifact examination and timeline analysis. The workflow transforms raw LCQL query results and collected evidence into structured, evidence-backed narratives that ensure traceability and support post-incident investigations.

Does LimaCharlie support post-incident forensics for registry and network analysis?

Yes, LimaCharlie supports post-incident forensics through comprehensive registry and network analysis. The forensic workflow guides analysts through targeted artifact review, applying LCQL queries to extract registry keys and network artifacts to reconstruct attacker movement and generate defensible reports.