report-forensic

Compile forensic findings into a structured, legally defensible report.

Updated Jul 30, 2026
One-click install
npx skills add https://github.com/salmanabdurrahman/pi-pentest-agent --skill report-forensic
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: report-forensic
Source: https://github.com/salmanabdurrahman/pi-pentest-agent/tree/main/skills/report-forensic
Command: npx skills add https://github.com/salmanabdurrahman/pi-pentest-agent --skill report-forensic

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This skill solves the challenge of manually synthesizing complex, multi-source forensic evidence into a structured, legally defensible report that meets regulatory and executive standards.

Core Features & Use Cases

  • Structured Reporting: Automatically compiles evidence manifests, timelines, and attack-chain mappings into a cohesive document.
  • Evidence Integrity: Ensures all findings are linked to pre-hashed evidence, maintaining a strict chain-of-custody.
  • Use Case: Following a security incident, use this skill to generate a comprehensive forensic report for insurance claims and executive review, ensuring all findings are mapped to the MITRE ATT&CK framework.

Quick Start

Use the report-forensic skill to compile the final incident report using the evidence and findings currently loaded in the active engagement session.

Frequently Asked Questions about report-forensic

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I generate a forensic incident report from digital evidence?

To generate a forensic incident report, you compile preserved and hashed digital evidence into a structured document. This process synthesizes evidence manifests, timelines, and attack-chain mappings for executive review and legal defense.

How do I map an attack chain to the MITRE ATT&CK framework for an incident response report?

Mapping an attack chain to the MITRE ATT&CK framework involves aligning forensic investigation findings with corresponding tactics and techniques. This structured attack-chain mapping ensures the final incident report meets regulatory compliance and executive review standards.

Does generating a legally defensible forensic report require a chain-of-custody manifest?

Yes, generating a legally defensible forensic report requires a strict chain-of-custody. The process integrates established evidence manifests and findings inventories to ensure all compiled findings are linked to pre-hashed digital evidence.

What is the best way to compile an IOC inventory for a cybersecurity incident report?

The best way to compile an IOC inventory for a cybersecurity incident report is to integrate established findings inventories with timeline reconstruction. This ensures all indicators of compromise are structurally linked to hashed evidence for regulatory compliance.

Can I use forensic findings to reconstruct an incident timeline for insurance claims?

Yes, you can use forensic findings to reconstruct an incident timeline for insurance claims. The process compiles multi-source evidence manifests into a cohesive, legally defensible report supporting both insurance claims and executive review.