Investigation Section Chief (DFIR — NIMS ICS Role)

Orchestrate DFIR investigations with authority-gated decisions and Common Operating Picture updates.

1|Updated Apr 25, 2026
One-click install
npx skills add https://github.com/rjonhaas/SIFTics --skill investigation-section-chief-dfir-nims-ics-role
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: Investigation Section Chief (DFIR — NIMS ICS Role)
Source: https://github.com/rjonhaas/SIFTics/tree/main/skills/investigation-section-chief
Command: npx skills add https://github.com/rjonhaas/SIFTics --skill investigation-section-chief-dfir-nims-ics-role

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

It orchestrates a DFIR investigation lifecycle by defining the Investigation Section Chief role, enforcing authority boundaries, managing operational-period analysis, and producing a continuously reviewed Common Operating Picture (COP).

Core Features & Use Cases

  • Authority-gated investigation decisions: Records chain-of-custody failures, scope expansion candidates, contradictions, and closure recommendations for IC ratification without halting analysis.
  • Structured, period-based investigation management: Caps analysis at 4 operational periods, drives COP updates each period, and maintains a pivot ledger of outstanding actions triggered by findings.
  • Evidence integrity and temporal strategy: Performs evidence inventory, chain-of-custody verification/gap documentation, and selects analysis order based on evidence relationship to the suspected attack window.

Quick Start

Have the Incident Commander invoke the Investigation Section Chief skill at case start and follow its Phase 0 initialization steps to generate and update the COP based on the available evidence.

Frequently Asked Questions about Investigation Section Chief (DFIR — NIMS ICS Role)

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I manage a DFIR investigation under incident command authority?

Manage a DFIR investigation by invoking an Investigation Section Chief role to orchestrate authority gates, route domain analysis, and maintain a Common Operating Picture for Incident Commander ratification.

What is a Common Operating Picture in digital forensics and incident response?

A Common Operating Picture in DFIR is a continuously reviewed record that tracks evidence inventory, chain-of-custody status, and classified findings to synchronize multi-period investigation analysis.

How do I maintain chain of custody during incident response evidence triage?

Maintain chain of custody during evidence triage by using verification and generation modes to document evidence integrity gaps, ensuring all findings are routed under incident command authority gates.

Can I use NIMS ICS roles to structure operational periods in a DFIR case?

Yes, you can structure DFIR cases using NIMS ICS roles by capping analysis at a maximum of four operational periods, driving Common Operating Picture updates each period, and enforcing closure recommendations.

What is the best way to re-synchronize a stalled digital forensics investigation mid-case?

Re-synchronize a stalled DFIR investigation mid-case by re-initializing the Common Operating Picture, reviewing the pivot ledger of outstanding actions, and classifying findings as confirmed, inferred, or contradicted.

Why does my DFIR investigation require classifying findings as confirmed, inferred, or contradicted?

DFIR investigations require classifying findings as confirmed, inferred, or contradicted to maintain evidence integrity, manage scope expansion candidates, and resolve contradictions for incident command ratification.