forensic-triage

Automate forensic triage by collecting disk, memory, and log evidence to build an incident timeline.

6|Updated May 30, 2026
One-click install
npx skills add https://github.com/jassics/awesome-claude-security --skill forensic-triage
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: forensic-triage
Source: https://github.com/jassics/awesome-claude-security/tree/main/plugins/dfir/skills/forensic-triage
Command: npx skills add https://github.com/jassics/awesome-claude-security --skill forensic-triage

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill automates the process of forensic triage on a host or artifacts, collecting and analyzing disk, memory, and log evidence to build an incident timeline.

Core Features & Use Cases

  • Evidence Collection: Gather disk, memory, and log evidence with proper handling.
  • Timeline Building: Create a chronological record of attacker actions.
  • Scope Estimation: Determine the extent of the incident and affected systems.
  • ATT&CK Mapping: Tag observed techniques for detection and follow-up.
  • Use Case: Ideal for investigating a compromised system or for incident response teams to scope an incident and preserve evidence integrity.

Quick Start

Use the forensic-triage skill to analyze the system 'host-123' and generate a triage report.

Frequently Asked Questions about forensic-triage

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate forensic triage on a compromised system?

Forensic triage on a compromised system is automated by collecting and analyzing disk, memory, and log evidence to build a chronological incident timeline. This Skill requires appropriate external tools for evidence collection and analysis to determine the extent of the incident.

What is the best way to build an incident timeline from memory and disk evidence?

Building an incident timeline from memory and disk evidence involves gathering artifacts with proper handling and creating a chronological record of attacker actions. The process tags observed techniques using ATT&CK mapping for follow-up detection and scope estimation.

Can I use this approach to map attacker techniques to the ATT&CK framework?

Yes, you can map attacker techniques to the ATT&CK framework during the forensic triage process. The Skill tags observed techniques from the collected disk, memory, and log evidence to enhance detection and guide follow-up incident response actions.

Do I need specific tools to perform evidence collection and analysis?

Yes, you need appropriate external tools to perform evidence collection and analysis. The Skill automates the triage workflow and builds the incident timeline, but it requires separate tools to gather and process the disk, memory, and log evidence from the compromised host.

When do I need forensic triage for incident response?

You need forensic triage for incident response when investigating a compromised system or scoping an incident. It is used to determine the extent of the attack, identify affected systems, and preserve evidence integrity by collecting disk, memory, and log data.