Skip to main content
Run any Skill in Manus
with one click

disk-triage-hunter

Stars15
Forks7
UpdatedJune 28, 2026 at 16:46

Triages an acquired disk image (read-only, hash-verified copy) during an authorized incident using The Sleuth Kit and plaso. Recovers the partition/filesystem layout, deleted files, and key host-forensic artifacts - Windows $MFT/$UsnJrnl, registry hives (Amcache/Shimcache/Run keys), Prefetch, scheduled tasks, services, WMI persistence, browser history, LNK/jumplists; Linux cron/systemd, auth logs, shell history, SSH authorized_keys - and builds a filesystem timeline. Surfaces persistence, execution, and anti-forensics evidence mapped to MITRE ATT&CK. Use when a disk image exists in Detection & Analysis. Requires .claude/security-scope.yaml dfir_scope.incident_response: approved and evidence from dfir_scope.evidence_store_path. Read-only on evidence copies; no containment. Grounded in incident-response.

Installation

Install with Codex or Claude Copy this prompt, paste it into Codex, Claude, or another assistant, and let it review the skill page and install it for you.

SKILL.md
readonly