performing-disk-forensics-investigation

Featured

Conducts disk forensics investigations using forensic imaging, file system analysis, artifact recovery, and timeline reconstruction to support incident response cases. Utilizes tools such as FTK Imager, Autopsy, and The Sleuth Kit for evidence acquisition, deleted file recovery, and artifact examination. Activates for requests involving disk forensics, hard drive analysis, forensic imaging, file recovery, evidence acquisition, or digital forensic investigation.

AI & Automation 12,642 stars 1468 forks Updated today Apache-2.0

Install

View on GitHub

Quality Score: 99/100

Stars 20%
100
Recency 20%
100
Frontmatter 20%
70
Documentation 15%
100
Issue Health 10%
50
License 10%
100
Description 5%
100

Skill Content

# Performing Disk Forensics Investigation ## When to Use - A security incident requires forensic analysis of a system's persistent storage - Evidence preservation is needed for potential legal proceedings or HR investigations - Deleted files, browser history, or application artifacts must be recovered - A timeline of user or adversary activity must be reconstructed from file system metadata - Malware persistence mechanisms stored on disk need identification and documentation **Do not use** for volatile evidence (running processes, network connections); use memory forensics with Volatility instead. ## Prerequisites - Forensic workstation with write-blocking hardware or software (Tableau T35u, Arsenal Image Mounter) - Forensic imaging software: FTK Imager, Guymager, or dd with dcfldd - Analysis platform: Autopsy, FTK (Forensic Toolkit), or X-Ways Forensics - Sufficient storage (2-3x the target drive size for image plus working copies) - Chain of custody forms and evidence bags for physical media - Hash verification tools for evidence integrity (SHA-256) ## Workflow ### Step 1: Secure and Document the Evidence Before touching any storage media, establish chain of custody: - Photograph the system, noting serial numbers, labels, and cable connections - Document the evidence source: device type, make, model, serial number, capacity - Complete chain of custody form with date, time, handler name, and reason for acquisition - Use a hardware write blocker when connecting the e...

Details

Author
mukul975
Repository
mukul975/Anthropic-Cybersecurity-Skills
Created
3 months ago
Last Updated
today
Language
Python
License
Apache-2.0

Similar Skills

Semantically similar based on skill content — not just same category

API & Backend Featured

performing-endpoint-forensics-investigation

Performs digital forensics investigation on compromised endpoints including memory acquisition, disk imaging, artifact analysis, and timeline reconstruction. Use when investigating security incidents, collecting evidence for legal proceedings, or analyzing endpoint compromise scope. Activates for requests involving endpoint forensics, memory analysis, disk forensics, or incident investigation.

12,642 Updated today
mukul975
AI & Automation Featured

analyzing-disk-image-with-autopsy

Perform comprehensive forensic analysis of disk images using Autopsy to recover files, examine artifacts, and build investigation timelines.

12,642 Updated today
mukul975
AI & Automation Listed

analyzing-disk-image-with-autopsy

Perform comprehensive forensic analysis of disk images using Autopsy to recover files, examine artifacts, and build investigation timelines.

6 Updated today
26zl
AI & Automation Listed

forensics-assist

Digital-forensics assistant for IR context — memory analysis via Volatility 3, disk-imaging hygiene (write-blocker, hash validation), timeline reconstruction via plaso/log2timeline, file-system artifacts per OS. Audit-grade evidence; courtroom-grade chain of custody requires additional specialized forensics work.

4 Updated 1 weeks ago
roodlicht
AI & Automation Featured

acquiring-disk-image-with-dd-and-dcfldd

Create forensically sound bit-for-bit disk images using dd and dcfldd while preserving evidence integrity through hash verification.

12,642 Updated today
mukul975