Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
daemon-blockint-tech avatar

Digital Forensics Analyst

  • 27 installs
  • 7 repo stars
  • Updated May 20, 2026
  • daemon-blockint-tech/agentic-enteprises-skill

Guides digital forensics for security incidents: evidence acquisition with chain of custody, disk/memory/cloud artifact analysis, super-timelines, and forensic reports.

About

Guides digital forensics work including evidence acquisition and chain of custody, host/memory/network/cloud artifact analysis, timeline correlation, and malware artifact triage. A developer uses it when preserving and analyzing forensic artifacts or preparing factual investigation reports for IR and legal.

  • Acquisition-to-custody flow with write blockers and per-item worksheets
  • UTC-normalized super-timelines separating facts from inferences

Digital Forensics Analyst by the numbers

  • 27 all-time installs (skills.sh)
  • Ranked #1,533 of 2,203 Security skills by installs in the Skillselion catalog
  • Data as of Jul 29, 2026 (Skillselion catalog sync)
npx skills add https://github.com/daemon-blockint-tech/agentic-enteprises-skill --skill digital-forensics-analyst

Add your badge

Show developers this skill is listed on Skillselion. Paste this into your README.

Listed on Skillselion
Installs27
repo stars7
Last updatedMay 20, 2026
Repositorydaemon-blockint-tech/agentic-enteprises-skill

What it does

Guides digital forensics for security incidents: evidence acquisition with chain of custody, disk/memory/cloud artifact analysis, super-timelines, and forensic reports.

Files

SKILL.mdMarkdownGitHub ↗

Digital Forensics Analyst

When to Use

  • Plan and execute evidence acquisition with documented chain of custody
  • Analyze host, disk, memory, mobile, and cloud artifacts after preservation
  • Perform log, network, and cloud audit forensics with cited sources
  • Build super-timelines correlating UTC-normalized events across systems
  • Triage malware artifacts (hash, static/dynamic notes) without live detonation in prod
  • Draft forensic investigation reports for IR, legal, or insurance (factual, not legal advice)
  • Prepare expert witness preparation outlines (topics, exhibits, foundation)—not testimony strategy from counsel

When NOT to Use

  • Run live incident command, war room, or executive comms cadence → incident-responder
  • Triage SIEM/EDR alert queues or execute Tier 1–3 SOC playbooks → soc-analyst
  • Proactive hypothesis-driven hunts across live telemetry → threat-hunter
  • Authorized exploitation or pentest → penetration-tester
  • Deep binary, firmware, or protocol reverse engineering → reverse-engineer
  • LLM/agent adversarial testing → ai-redteam
  • Design enterprise security strategy, policies, or GRC programs → cybersecurity
  • Implement IAM, SIEM parsers, EDR, or security guardrails → information-security-engineer
  • Map frameworks to audit evidence or continuous compliance monitoring → compliance-engineer
  • Implement cloud org guardrails, CSPM remediation, or landing zone security → cloud-security-engineer

Related skills

NeedSkill
Live incident command, containment cadence, stakeholder updatesincident-responder
Alert triage, SIEM/SOAR playbooks, shift handoffsoc-analyst
Proactive hunts before forensic acquisition is neededthreat-hunter
Security program, IR strategy, board narrativescybersecurity
SIEM/EDR integration and control implementationinformation-security-engineer
Cloud audit logs and misconfiguration forensicscloud-security-engineer
Audit evidence and control mappingcompliance-engineer
Authorized pentestpenetration-tester
Binary/firmware/protocol RE, patch diffreverse-engineer
LLM/adversarial AI testingai-redteam
On-call, SEV, postmortem program designincident-management-engineer
Crisis and security incident messagingcommunication-lead

Core Workflows

1. Scope and legal/IR coordination

1. Confirm authorization (internal counsel, contract, law enforcement liaison as applicable) 2. Define objectives (what questions must artifacts answer) 3. Identify custodians, systems, and data classes in scope 4. Agree preservation before remediation; document what was touched pre-acquisition 5. Route legal questions to counsel; produce factual findings only

See `references/digital_forensics_scope.md` for role boundaries and engagement types.

2. Evidence acquisition and chain of custody

identify sources → prioritize volatile → acquire → hash → seal → log transfers
  • Use write blockers or cloud-native snapshots per platform policy
  • Record who, what, when, where, how for every collection and handoff
  • Maintain master evidence log and per-item worksheets

See `references/evidence_acquisition_chain_of_custody.md` for worksheets and custody rules.

3. Host, disk, and memory artifacts

  • Prioritize volatile data when still available (memory, network connections, logged-on users)
  • Image disks or collect targeted logical collections when full imaging is impractical
  • Parse OS artifacts: registry, prefetch, shimcache, event logs, shellbags, browser, execution traces
  • Document tooling versions and parsing assumptions

See `references/host_and_memory_artifacts.md` for artifact categories and analysis order.

4. Network, log, and cloud forensics

  • Normalize timestamps to UTC; cite log source and retention limits
  • Correlate firewall, proxy, DNS, IdP, EDR, and cloud audit trails
  • Export cloud evidence via audit logs, snapshots, and API per provider runbook
  • Flag gaps (retention, missing sensors) explicitly in the report

See `references/network_log_and_cloud_forensics.md` for source matrix and export patterns.

5. Timeline correlation and reporting

  • Build super-timeline merging host, network, cloud, and identity events
  • Separate facts from inferences; label confidence (confirmed, likely, speculative)
  • Produce executive summary, technical appendix, IOC list, and open questions
  • Prepare expert witness outline (exhibit list, methodology summary)—not legal conclusions

See `references/timeline_correlation_and_reporting.md` for report sections and timeline fields.

6. Malware artifact triage

  • Work in isolated lab; never execute unknown samples on production networks
  • Capture hashes, strings, metadata, and sandbox output per policy
  • Map behaviors to MITRE ATT&CK where useful; link to host/network findings
  • Package IOC exports for SOC blocklists via soc-analyst handoff

See `references/malware_artifact_triage.md` for safe triage workflow.

When to load references

  • Role boundary and engagement typesreferences/digital_forensics_scope.md
  • Acquisition and chain of custodyreferences/evidence_acquisition_chain_of_custody.md
  • Host, disk, memory artifactsreferences/host_and_memory_artifacts.md
  • Network, log, cloud forensicsreferences/network_log_and_cloud_forensics.md
  • Timelines and reportsreferences/timeline_correlation_and_reporting.md
  • Malware triagereferences/malware_artifact_triage.md

Outputs

  • Evidence acquisition plan — sources, order, tools, approvers
  • Chain-of-custody log — item IDs, hashes, custodians, transfers
  • Super-timeline — UTC events with source citations
  • Forensic investigation report — facts, artifacts, methodology, gaps
  • Malware triage sheet — hashes, behaviors, IOCs, lab notes
  • Expert witness prep outline — topics, exhibits, foundation checklist (for counsel review)

Principles

  • Preserve first — acquisition before destructive remediation when feasible
  • Document everything — if it is not logged, it did not happen for counsel
  • UTC and cite sources — every timeline row has provenance
  • Separate fact from inference — confidence labels reduce dispute risk
  • Not legal advice — coordinate with counsel; do not opine on liability or guilt

Related skills

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.