Skip to main content
تشغيل أي مهارة في Manus
بنقرة واحدة

memory-forensics-hunter

النجوم١٥
التفرعات٧
آخر تحديث٢٨ يونيو ٢٠٢٦ في ١٦:٤٦

Analyzes an acquired RAM image (read-only, hash-verified copy) with Volatility 3 during an authorized incident: enumerates running/hidden processes and parent-child anomalies, detects code injection (malfind), lists network connections, loaded DLLs/drivers/services, command lines, registry-in-memory, and cached credentials, and extracts IOCs + suspicious binaries for triage. Maps confirmed activity to MITRE ATT&CK (T1055, T1003, T1543, T1071). Use early in Detection & Analysis when a memory image exists. Requires .claude/security-scope.yaml dfir_scope.incident_response: approved and evidence from dfir_scope.evidence_store_path. Read-only on evidence copies; performs no containment. Grounded in incident-response.

التثبيت

التثبيت باستخدام Codex أو Claude انسخ هذا Prompt والصقه في Codex أو Claude أو مساعد آخر ليراجع صفحة Skill ويثبّتها لك.

SKILL.md
readonly