ClaudeSuperPower

dfir

Skill

Digital forensics and incident response - Windows event log analysis, PCAP forensics, filesystem artifact analysis, AD attack detection, and timeline correlation. Use when investigating security incidents, analyzing Sherlocks, or performing threat hunting on provided evidence files.

Install

git clone https://github.com/transilienceai/communitytools.git ~/.claude/skills/dfir

What is dfir?

Digital forensics and incident response - Windows event log analysis, PCAP forensics, filesystem artifact analysis, AD attack detection, and timeline correlation. Use when investigating security incidents, analyzing Sherlocks, or performing threat hunting on provided evidence files.

What this can do

Capabilities declared in this component's own frontmatter — not inferred.

Inherit all session tools

Declares no tool restrictions — inherits every session tool

~71 tokens of context used while enabled, before you invoke anything

Documentation

README · ~4 min read

DFIR

Investigate security incidents by analyzing event logs, network captures, and filesystem artifacts. Detect and reconstruct AD attack chains.

Techniques

DomainKey Capabilities
Windows Event LogsEVTX parsing, Event ID correlation, logon tracking, privilege enumeration
Network ForensicsPCAP analysis, NTLM extraction, LLMNR/NBT-NS poisoning detection, relay identification
Filesystem ForensicsMFT parsing, Prefetch analysis, VSS artifact recovery, Linux persistence, timeline reconstruction
AD Attack DetectionKerberoasting, AS-REP roasting, NTDS dump, NTLM relay, credential theft
Memory ForensicsVolatility3 analysis: process trees, file extraction, SID resolution, command lines

Reviews

Log in to leave a review.

No reviews yet — be the first.

Explore related

Other things in this space — across every part of the ecosystem, not just skills.

Skillssimilar to this one

All skills