Skip to main content

tsale/awesome-dfir-skills

SkillsMP a collecté 8 skills depuis tsale/awesome-dfir-skills. Ouvrez un skill pour examiner sa source et ses détails.

Dernière activité source enregistrée
Catalogue SkillsMP mis à jour
skills collectés
8
Étoiles GitHub
321
Forks GitHub
35

Skills dans ce dépôt

1 catégories métier · 100% classifié

Affichage de 8 skills collectés sur 8.

métier
Analystes en sécurité de l'information
description

Apply the NATO Admiralty System (AJP-2.1) to assess source reliability and information credibility in cyber threat intelligence, OSINT, and breach analysis. Use this skill whenever you need to evaluate a CTI report, breach claim, dark web forum post, threat…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Build structured threat actor profiles using the 5W1H framework and the Diamond Model. Use this skill whenever the user wants to profile a threat actor, create a TA report, analyze an APT group, build an adversary profile, assess threat actor capability, map…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Help users write, validate, and troubleshoot osquery SQL queries using provided osquery table schemas as the authoritative source.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Professional malware analysis workflow for PE executables and suspicious files. Triggers on file uploads with requests like "analyze this malware", "analyze this sample", "what does this executable do", "check this file for malware", or any request to examine…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Analyse Mitre ATT&CK tactics, techniques and sub-techniques. Use when performing analysis of threat detections, threat models, security risks or cyber threat intelligence

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Create a targeted intrusion timeline for a Windows incident using whatever artifacts are available (event logs, EDR, SIEM exports, triage notes).

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Hypothesis-driven hunt plan for suspicious PowerShell, plus query snippets for common telemetry.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

First-hour intake checklist + questions that produce an actionable scope and evidence plan.

Langue du texte source : anglais

mis à jour
Affichage de 8 skills collectés sur 8.