Source

tsale/awesome-dfir-skills

9 skills · 120 combined installs

Skills from this source

#
Skill
Source
8W Activity
Installs
1
malware-analysis Professional malware analysis workflow for PE executables and suspicious files. Triggers on file uploads with request…
tsale/awesome-dfir-skills
73
2
analysing-attack Analyse Mitre ATT&CK tactics, techniques and sub-techniques. Use when performing analysis of threat detections, threa…
tsale/awesome-dfir-skills
11
3
osquery-query-helper Help users write, validate, and troubleshoot osquery SQL queries using provided osquery table schemas as the authorit…
tsale/awesome-dfir-skills
11
4
threat-actor-profiling Build structured threat actor profiles using the 5W1H framework and the Diamond Model. Use this skill whenever the us…
tsale/awesome-dfir-skills
7
5
admiralty-system Apply the NATO Admiralty System (AJP-2.1) to assess source reliability and information credibility in cyber threat in…
tsale/awesome-dfir-skills
6
6
Initial incident intake & scoping First-hour intake checklist + questions that produce an actionable scope and evidence plan.
tsale/awesome-dfir-skills
4
7
Suspicious PowerShell hunt (cross-platform ideas) Hypothesis-driven hunt plan for suspicious PowerShell, plus query snippets for common telemetry.
tsale/awesome-dfir-skills
4
8
Windows intrusion timeline (targeted) Create a targeted intrusion timeline for a Windows incident using whatever artifacts are available (event logs, EDR, …
tsale/awesome-dfir-skills
4
9
initial-incident-intake-&-scoping initial-incident-intake-&-scoping — an installable skill for AI agents, published by tsale/awesome-dfir-skills.
tsale/awesome-dfir-skills
0