Skip to main content

kismatkunwar89/SAVVYDFIR-MCP

SkillsMP 已收集 kismatkunwar89/SAVVYDFIR-MCP 中的 5 个 Skill。打开任一 Skill 可查看来源和详情。

最近记录的来源活动
SkillsMP 收录数据更新
已收集 skills
5
GitHub 星标
4
GitHub Forks
1

这个仓库中的 skills

1 个职业分类 · 已分类 100%

已展示 5 / 5 个已收集 Skill。

职业分类
信息安全分析师
描述

Load when you need to determine which forensic tool to use for a specific Windows artifact type. Maps artifact categories to exact MCP tools and Bash commands using the Practical Windows Forensics taxonomy.

原文语言:英语

更新
职业分类
信息安全分析师
描述

REQUIRED when the user says "start investigation", "investigate", "analyze case", "Read case-templates/manifest.json", references a manifest.json, or provides a SAVVYDFIR-MCP case_id. Defines the 5-phase DFIR methodology from evidence mounting through report…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Load when you have an initial finding and need to determine what to investigate next. Defines universal pivot chains from each artifact type to related evidence, enabling systematic investigation expansion.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Load when running sigma_scan(), interpreting anomaly results, or mapping findings to MITRE ATT&CK techniques. Covers all 5 universal detectors, severity levels, and pivot patterns from each detection type.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Load when you need exact command syntax for SIFT Workstation tools. Covers Volatility 3, Sleuth Kit, EZ Tools, Plaso, YARA, and Regripper with actual invocation examples and output parsing guidance.

原文语言:英语

更新
已展示 5 / 5 个已收集 Skill。