agentic/code/frameworks/forensics-complete/skills/forensics-quickref/SKILL.md
AUTO-INVOKE when user mentions forensics, incident response, IOC, log analysis, evidence preservation, breach investigation, threat hunting, attack timeline. Forensics framework quick reference — discovery phrases for incident response, log analysis, evidence preservation, IOC extraction.
npx skillsauth add jmagly/aiwg forensics-quickrefInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
This is your always-loaded directory for the AIWG forensics-complete framework. It does not list every skill. Instead, it teaches the framework's mental model and gives you curated search phrases that map to aiwg discover lookups.
When you find a candidate via aiwg discover, fetch its body with aiwg show <type> <name>. Never use find, ls, Glob, or direct Read on <provider>/skills/ paths — those reflect the kernel-pivot deploy state, not the full surface.
aiwg discover "<phrase>" # find — returns ranked candidates
aiwg show skill <name> # fetch — streams the SKILL.md body
If your platform's Skill tool errors on a non-kernel skill (expected — most aren't kernel), the fallback is aiwg show, never filesystem browsing. Last-resort if aiwg itself is broken: read directly from $AIWG_ROOT/agentic/code/... (the canonical corpus, always present).
aiwg discover "<phrase>" and surface the top match (or top-3) to the userDo not enumerate skills from memory. The framework ships ~20 skills and discovery is the lookup surface.
Digital forensics & incident response. RFC 3227-aligned triage, multi-source timeline reconstruction, IOC extraction, chain-of-custody preservation, and Sigma-rule-based threat hunting. Multi-platform (Linux / cloud / containers / memory).
| Domain | Covers | |---|---| | Triage & acquisition | Quick host triage following RFC 3227, evidence acquisition with chain of custody, target system profiling | | Platform-specific analysis | Linux, memory dumps, cloud (AWS/Azure/GCP), Docker/K8s containers, supply chain | | Investigation orchestration | Full multi-agent investigation, log correlation, IOC extraction & STIX 2.1 mapping | | Threat hunting | Sigma rule application across log sources | | Reporting | Investigation reports with evidence, timeline reconstruction |
aiwg discover "forensic triage" # → forensics-triage
aiwg discover "evidence acquisition" # → forensics-acquire (score 0.55)
aiwg discover "target system profile" # → forensics-profile
aiwg discover "start forensics case" # → forensics-quickref / forensics-investigate
aiwg discover "linux forensics" # → linux-forensics (score 0.51)
aiwg discover "memory forensics" # → memory-forensics (score 0.94)
aiwg discover "cloud forensics" # → cloud-forensics (score 0.63)
aiwg discover "container forensics" # → container-forensics
aiwg discover "supply chain compromise" # → supply-chain-forensics
aiwg discover "forensics investigation" # → forensics-investigate (top-3; refine if needed)
aiwg discover "log analysis" # → log-analysis
aiwg discover "extract iocs" # → forensics-ioc
aiwg discover "build forensic timeline" # → forensics-timeline
aiwg discover "threat hunt with sigma rules" # → sigma-hunting (score 1.00)
aiwg discover "forensics hunt" # → forensics-hunt
aiwg discover "forensic report" # → forensics-report
aiwg discover "investigation status" # → forensics-status
aiwg discover "evidence preservation" # → evidence-preservation
aiwg discover "integrity verification" # → integrity-verification
Triage (RFC 3227) → Acquisition → Platform analysis → IOC extraction → Reporting
forensics-triage forensics-acquire linux-forensics forensics-ioc forensics-report
memory-forensics
cloud-forensics
container-forensics
Cross-cutting: forensics-hunt (Sigma) and log-analysis (correlation) feed both Analysis and IOC extraction.
Forensic artifacts go under .aiwg/forensics/ when the framework is in use:
.aiwg/forensics/
├── profiles/ # Target profiles
├── plans/ # Investigation plans
├── triage/ # RFC 3227 quick captures and summaries
├── evidence/ # Chain-of-custody-preserved evidence
├── findings/ # Analysis findings
├── timelines/ # Reconstructed event timelines
├── iocs/ # Extracted indicators of compromise
├── reports/ # Investigation reports
├── sigma/ # Custom Sigma rules
└── chain-of-custody.md # Master CoC log
For readiness and handoff from preventive security work, use security-engineering/dfir-readiness. For production incident coordination, use SDLC incident-response flows. See docs/integrations/dfir-handoff.md.
aiwg discover "<your need, paraphrased>" --limit 5
If the top-3 results all score below ~0.20, the framework genuinely may not have a curated skill for that need. Then improvise — but always check first.
If a user asks "what forensics skills are available?", do not list from this skill. Run:
aiwg discover --type skill --limit 20 "<their interest area>"
This skill is the orientation layer. The index is the lookup.
data-ai
Report which research-corpus radar sidecars are overdue for refresh. Computes staleness (days since last refresh vs the cadence window) for every radar, sorted most-overdue-first. Runs via `aiwg corpus radar-status`.
data-ai
Aggregate research-corpus radar sidecars into a corpus or per-cluster freshness report — totals, overdue count, per-cluster / per-GRADE / per-trajectory breakdowns, an overdue table, and per-radar rationale snippets. Runs via `aiwg corpus radar-report`.
testing
Scaffold radar/freshness sidecars for research-corpus REFs. Pulls title/authors from the citation sidecar and GRADE from the analysis doc, defaults the refresh cadence from GRADE and the cluster from a corpus-local map, and stamps documentation/radar/REF-XXX-radar.md. Runs via `aiwg corpus radar-init`.
data-ai
Compute an entity's publication trajectory — per-year paper counts, topic drift, hot-streak detection (≥3 consecutive A-grade years), and career phase. Runs via `aiwg corpus profile-temporal`.