一键导入
memory-forensics
Analyze a memory dump — process analysis, network connections, persistence mechanisms, malware detection with Volatility3, and reporting.
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
菜单
Analyze a memory dump — process analysis, network connections, persistence mechanisms, malware detection with Volatility3, and reporting.
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
基于 SOC 职业分类
Run a full 11-phase forensic investigation across all MCP servers — disk, memory, Windows artifacts, malware, network, OSINT, threat intel, timeline, and reporting.
Run a 6-phase forensic investigation — evidence intake, artifact collection, network analysis, threat intel, timeline reconstruction, and reporting.
Run a 7-phase incident response — triage, containment assessment, evidence collection, attack chain reconstruction, threat intel, impact assessment, and reporting.
Analyze a malware sample — static analysis with Ghidra/Radare2/Capa, YARA scanning, string extraction, and VirusTotal/MalwareBazaar lookup.
Analyze network traffic — PCAP triage, protocol analysis, anomaly detection, IoC extraction, stream reconstruction, and reporting.
Investigate a domain — DNS/subdomain enumeration, infrastructure analysis, threat assessment, web presence mapping, and reporting.
| name | memory-forensics |
| description | Analyze a memory dump — process analysis, network connections, persistence mechanisms, malware detection with Volatility3, and reporting. |
Perform memory forensics analysis on the specified target.
Usage: /memory-forensics <target>
Where <target> is the memory dump path — e.g. /evidence/memdump.raw, /evidence/memory.dmp.
If no target is provided, ask the user for the memory dump location.
get_template(name="memory-forensics", target="$ARGUMENTS")