investigation-ingest

Integrate raw forensic outputs into investigation documentation and update reports and spreadsheet links.

Updated Aug 27, 2026
One-click install
npx skills add https://github.com/mgreen27/dfir-skills --skill investigation-ingest
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: investigation-ingest
Source: https://github.com/mgreen27/dfir-skills/tree/main/skills/investigation-ingest
Command: npx skills add https://github.com/mgreen27/dfir-skills --skill investigation-ingest

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

It ensures that raw DFIR outputs are efficiently integrated into the investigation case folder, keeping artifact notes, links, and structured records synchronized and current.

Core Features & Use Cases

  • Artifact and Evidence Synchronization: Imports new Velociraptor or Volatility results into wiki artifact notes.
  • Metadata and Link Refresh: Updates evidence summaries, Spreadsheet of Doom pages, and export files.
  • Use Case: When new raw forensic data lands, analysts can automatically refresh case documentation, maintaining an accurate, comprehensive case overview.

Quick Start

Use this Skill to sync investigation data after collecting new evidence to update reports and links automatically.

Frequently Asked Questions about investigation-ingest

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate updating investigation case records with new forensic outputs?

Automating investigation case records involves integrating new raw forensic outputs into case documentation and automatically updating associated reports and spreadsheet links to maintain synchronized case overviews.

Can I sync Velociraptor or Volatility results directly into case management documentation?

Yes, you can sync Velociraptor or Volatility results by importing new raw forensic data directly into wiki artifact notes and updating evidence summaries to keep case management documentation current.

What is the best way to keep incident response artifact notes and links up to date?

Keeping incident response artifact notes updated requires automatically refreshing case documentation, evidence summaries, and export links whenever new raw forensic data lands in the investigation case folder.

Do I need bash scripts and Python modules for forensic evidence synchronization?

Forensic evidence synchronization checks for dependencies like bash scripts and Python modules to automate the integration of raw forensic outputs into investigation documentation and maintain iterative analysis workflows.

When should I use automated case documentation updates during an incident response?

Automated case documentation updates are suitable during incident response when managing iterative analysis workflows and needing to automatically refresh reports, artifact notes, and links after collecting new raw evidence.