tools

List installed DFIR/SOC tools and skills with use-case mappings.

3|Updated Apr 10, 2026
One-click install
npx skills add https://github.com/Fuzzdkk/dfir-skills --skill tools-fuzzdkk
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: tools
Source: https://github.com/Fuzzdkk/dfir-skills/tree/main/tools
Command: npx skills add https://github.com/Fuzzdkk/dfir-skills --skill tools-fuzzdkk

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This reference consolidates available DFIR/SOC skills and installed forensic tools into a single, quick-access catalog for analysts.

Core Features & Use Cases

  • Inventory & mapping: List the available skills and installed tools with descriptions and use cases, enabling rapid onboarding and capability assessment.
  • Decision support: Provide a ready reference for tool selection and task planning during investigations and incident response.
  • Use Case: When starting a new case, quickly identify which tools are installed and which skills are available to outline the investigation plan.

Quick Start

Identify the tools installed on the system and summarize them for the incident response team.

Frequently Asked Questions about tools

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I create a DFIR tool inventory for incident response planning?

A DFIR tool inventory consolidates installed forensic tools and available SOC skills into a single catalog with descriptions and use cases. It enables rapid analyst onboarding and provides decision support for selecting appropriate tools during incident response planning and active malware analysis.

What is the best way to map forensic tools to typical DFIR use cases?

Mapping forensic tools to typical DFIR use cases involves listing available skills and installed tools with their descriptions to outline an investigation plan. This reference catalog enables quick capability assessment and task planning for memory forensics, network forensics, and malware analysis scenarios.

How do I quickly identify which forensic tools are installed for a new case?

To quickly identify installed forensic tools for a new case, summarize the available DFIR/SOC skills and tool inventory on the system. This provides the incident response team with an immediate capability assessment to outline the investigation plan.

Can I use a single catalog for both analyst onboarding and incident response planning?

Yes, you can use a single consolidated DFIR/SOC catalog for both analyst onboarding and incident response planning. By listing available skills and installed tools with use cases, it provides a quick-access reference for capability assessment and decision support during investigations.

Does a DFIR tool inventory cover memory forensics and network forensics capabilities?

A DFIR tool inventory covers memory forensics and network forensics capabilities by listing installed tools and available skills mapped to typical use cases. This ensures analysts can quickly identify the appropriate forensic tooling required for specific malware analysis investigations.