| namespace | aiwg |
| name | dfir-readiness |
| platforms | ["all"] |
| description | Use when a project needs DFIR readiness from the security-engineering side: prepare incident evidence handling, chain-of-custody expectations, IOC readiness, and handoff to forensics-complete without collecting evidence. |
| triggers | ["DFIR readiness","incident response readiness","evidence preservation readiness","chain of custody readiness","IOC readiness","forensic report readiness"] |
| requires | [{"project-context":"repository or workspace that may need evidence-bearing incident response"}] |
| ensures | [{"boundary-routing":"preventive security, production incident management, and forensic investigation responsibilities are separated"},{"forensics-handoff":"operator is routed to forensics-complete for evidence-bearing work"},{"readiness-record":"preparation notes can be written under .aiwg/security-engineering/incident-readiness/"}] |
| invariants | ["no live evidence collection happens from this skill","no containment, cleanup, or destructive action is suggested without explicit operator authorization","forensic case artifacts stay under .aiwg/forensics/"] |
DFIR Readiness
Use this skill when a security-engineering conversation turns into incident readiness: evidence handling, chain of custody, IOC workflow, forensic report readiness, or "what should this project have in place before an incident?"
This is a bridge. It prepares and routes. It does not replace forensics-complete, and it does not collect evidence.
Triggers
- "DFIR readiness"
- "incident response readiness"
- "evidence preservation readiness"
- "chain of custody readiness"
- "IOC readiness"
- "forensic report readiness"
- "prepare this project for a breach investigation"
- "start a forensics case safely"
- "what do we need before collecting evidence?"
Purpose
Make a security project ready to hand off to evidence-preserving DFIR work.
The skill answers three questions:
- Is this preventive security work, production incident coordination, or a forensic investigation?
- Is
forensics-complete installed for evidence-bearing work?
- What readiness record, custody expectation, and handoff steps should exist before anyone touches volatile or potentially admissible evidence?
Behavior
Boundary
| Need | Route |
|---|
| Preventive controls, disclosure intake, secure design decisions | security-engineering |
| Severity, incident bridge, stakeholder comms, service restoration, PIR | sdlc-complete incident-response flows |
| Evidence preservation, triage, acquisition, timelines, IOCs, reports | forensics-complete |
If a request includes live evidence, suspected compromise, a target host, IOC extraction, chain of custody, forensic timeline, or report generation, route to forensics-complete.
1. Classify the situation
Ask only enough to route safely:
- Is there an active incident, or is this readiness planning?
- Is any evidence already collected?
- Are any destructive containment or cleanup actions planned?
- Is legal, compliance, or customer-impact handling in scope?
- Which systems could hold volatile evidence?
Do not ask for secrets, exploit payloads, private vulnerability details, or raw evidence in chat.
2. Check for the DFIR framework