forensics-checklist

Automate digital forensic evidence collection and chain of custody documentation.

Updated Apr 19, 2026
One-click install
npx skills add https://github.com/do360now/security-agents --skill forensics-checklist
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: forensics-checklist
Source: https://github.com/do360now/security-agents/tree/main/.claude/skills/forensics-checklist
Command: npx skills add https://github.com/do360now/security-agents --skill forensics-checklist

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill assists security professionals in systematically collecting and documenting forensic evidence to support incident investigations and legal proceedings.

Core Features & Use Cases

  • Guided Evidence Collection: Provides comprehensive steps aligned with NIST and RFC standards for acquiring volatile and non-volatile data.
  • Chain of Custody Documentation: Generates detailed custody records ensuring evidentiary integrity.
  • Use Case: When responding to a security breach, execute this Skill to collect memory, disk images, and logs with verified hashes, maintaining compliance with forensic best practices.

Quick Start

Use the forensics-checklist skill to initiate evidence collection from the target system and generate a full report ready for case documentation.

Frequently Asked Questions about forensics-checklist

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I collect digital forensic evidence during incident response?

Digital forensic evidence collection is automated by this Skill, which systematically acquires volatile memory, disk images, and system logs while applying NIST and RFC standards for compliance.

How do I maintain chain of custody documentation for legal proceedings?

Chain of custody documentation is generated automatically with detailed custody records, ensuring evidentiary integrity and verified hashes for all acquired forensic data.

What is the best way to acquire volatile memory and disk images for forensic analysis?

Acquiring volatile memory and disk images is streamlined through guided evidence collection steps that capture target system data and generate a full report ready for case documentation.

Can I use this forensics checklist for cloud environments and system logs?

Yes, forensic evidence collection is fully applicable to cloud environments and system logs, ensuring proper handling protocols and evidence integrity across diverse targets.

When do I need to follow NIST and RFC standards for evidence collection?

You need to follow NIST and RFC standards for evidence collection when responding to a security breach to maintain compliance with forensic best practices and support legal proceedings.

Does this forensics tool generate verified hashes for collected evidence?

Yes, verified hashes are computed for collected evidence to maintain evidentiary integrity, which is critical for proper handling protocols and admissibility in legal proceedings.