incident-response
仓库创建 2026年5月19日最近提交 24 天前SkillHot 收录 21 天前
▸ 精选理由
便于 IR 团队快速进行取证、溯源与处置流程化工作。
▸ 风险提示
含取证与检测细节,亦可能被用于规避取证或逆向滥用。
这个 Skill 做什么
事故响应与取证流程、工具与调查方法的实用指南。
遇到安全事件或要做取证时用来分级处置、取证采集和时间线重建,常用工具有 Velociraptor/KAPE、Volatility 3 和 EVTX 分析。能帮你定位内存注入、日志篡改、抗取证手法和云端响应要点。重点是把现场证据按优先级安全拿到并判断攻击链,方便后续清理和追责。
▸ 展开 SKILL.md 英文原文
Use when responding to or forensically investigating an incident — triage acquisition (Velociraptor/KAPE), Volatility 3 memory forensics, Chainsaw/Hayabusa EVTX timelining, anti-forensics detection, cloud IR, ransomware/ESXi response
326
Stars
58
Forks
37
仓库内 Skill
+15
7 日增星
安装 / 使用
给你的 Agent 一句话(通用)
帮我安装这个 skill:https://raw.githubusercontent.com/hypnguyen1209/offensive-claude/main/skills/incident-response/SKILL.md或 curl 直取 SKILL.md
curl -fsSL "https://raw.githubusercontent.com/hypnguyen1209/offensive-claude/main/skills/incident-response/SKILL.md"SKILL.MD 节选查看完整文件 ↗
# Incident Response & Digital Forensics ## When to Activate - Active security incident: triage, scoping, evidence acquisition, containment, eradication - Memory forensics — process injection, rootkit (incl. eBPF), credential-theft, network artifacts - Windows event-log / artifact timelining and super-timeline reconstruction - Anti-forensics detection — timestomping, log clearing, secure deletion, VSS recovery - Cloud incident response — AWS/Azure/GCP identity-plane attacks and forensic collection - Ransomware / extortion response — hypervisor (ESXi) encryption, backup destruction, fast-dwell intrusions - Verifying suspect DFIR tooling used as adversary persistence (Velociraptor CVE-2025-62
via SKILL·HOT · 数据来自 GitHub 公开信息 · 原文版权归作者所有