From dfir
Perform forensic triage on a host or artifacts — collect and analyze disk, memory, and log evidence with proper handling, then build an incident timeline. Use to investigate a compromised system or scope an incident. Preserve evidence integrity.
How this skill is triggered — by the user, by Claude, or both
Slash command
/dfir:forensic-triageThe summary Claude sees in its skill listing — used to decide when to auto-load this skill
A defensible analysis of the available evidence that answers what happened, when, and
A defensible analysis of the available evidence that answers what happened, when, and how far it spread — with a timeline and chain of custody intact.
incident-response
reference); work on copies; hash and log every item (chain of custody).A triage report: evidence collected (with hashes) · key artifacts · timeline · scope/
dwell time · ATT&CK techniques · IOCs (hand to ioc-development). Use
security-reporting; visualize the timeline/attack path with security-diagramming.
Preserve before you analyze — and capture memory early, it's gone on reboot. A correct, source-correlated timeline in UTC is the backbone of the investigation. Maintain chain of custody if the findings might be used in legal/HR proceedings.
Provides behavioral guidelines to reduce common LLM coding mistakes, focusing on simplicity, surgical changes, assumption surfacing, and verifiable success criteria.
Searches, retrieves, and installs Agent Skills from prompts.chat registry using MCP tools like search_skills and get_skill. Activates for finding skills, browsing catalogs, or extending Claude.
npx claudepluginhub jassics/awesome-claude-security --plugin dfir