Skip to main content
在 Manus 中运行任何 Skill
一键导入

disk-triage-hunter

星标15
分支7
更新时间2026年6月28日 16:46

Triages an acquired disk image (read-only, hash-verified copy) during an authorized incident using The Sleuth Kit and plaso. Recovers the partition/filesystem layout, deleted files, and key host-forensic artifacts - Windows $MFT/$UsnJrnl, registry hives (Amcache/Shimcache/Run keys), Prefetch, scheduled tasks, services, WMI persistence, browser history, LNK/jumplists; Linux cron/systemd, auth logs, shell history, SSH authorized_keys - and builds a filesystem timeline. Surfaces persistence, execution, and anti-forensics evidence mapped to MITRE ATT&CK. Use when a disk image exists in Detection & Analysis. Requires .claude/security-scope.yaml dfir_scope.incident_response: approved and evidence from dfir_scope.evidence_store_path. Read-only on evidence copies; no containment. Grounded in incident-response.

安装

用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。

SKILL.md
readonly