forensics-investigator

Automate evidence collection, timeline reconstruction, and artifact analysis from memory, disk, log, and network data.

1|Updated Mar 13, 2026
One-click install
npx skills add https://github.com/coreymaypray/sloth-skill-tree --skill forensics-investigator
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: forensics-investigator
Source: https://github.com/coreymaypray/sloth-skill-tree/tree/main/plugins/maycrest-secure/skills/forensics-investigator
Command: npx skills add https://github.com/coreymaypray/sloth-skill-tree --skill forensics-investigator

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Efficiently conducts post-breach digital forensics by ensuring evidence handling, chain-of-custody, and defensible findings through integrated artifact analysis.

Core Features & Use Cases

  • End-to-end forensics workflow: memory, disk, log, and network data are analyzed to reconstruct an attack timeline.
  • Defensible reporting: creates evidence inventories, timelines, IOC extraction, and expert reports suitable for legal proceedings.
  • Incident-response integration: supports incident commanders by delivering actionable insights and audit-ready artifacts.

Quick Start

Provide a full evidence-based investigation and timeline by analyzing memory, disk, logs, and network artifacts.

Frequently Asked Questions about forensics-investigator

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I reconstruct an attack timeline from memory and disk forensics data?

Timeline reconstruction is achieved by processing memory, disk, log, and network artifacts to correlate events and extract IOCs. The Skill analyzes these data sources to build a precise forensic timeline and generate defensible findings for incident response.

What is the best way to automate evidence collection while maintaining chain-of-custody?

Automating evidence collection with strict chain-of-custody requires hash verification and validated tooling. The Skill enforces these controls during artifact analysis to produce audit-ready evidence inventories and expert reports suitable for legal proceedings.

Can I use this forensics workflow for insider threat investigations?

Yes, the forensics workflow is explicitly designed for insider threat investigations alongside post-breach analysis. It processes digital artifacts to deliver actionable insights and audit-ready outputs for incident commanders.

Does digital forensics reporting support IOC extraction for incident response?

Digital forensics reporting fully supports IOC extraction as part of its core workflow. It analyzes memory, disk, log, and network data to extract indicators of compromise and produce defensible expert reports.

What do I need to produce defensible findings for a breach investigation?

Producing defensible findings requires strict adherence to chain-of-custody, hash verification, and validated tooling. The Skill integrates these forensic processes to analyze artifacts and generate evidence inventories and expert reports.

When should I not use automated forensics for post-breach analysis?

Automated forensics should not be used without proper hash verification and validated tooling to ensure defensible findings. The Skill enforces chain-of-custody and strict evidence handling, but requires appropriate input data.