tsale/awesome-dfir-skills · Archived
Windows intrusion timeline (targeted)
Create a targeted intrusion timeline for a Windows incident using whatever artifacts are available (event logs, EDR, SIEM exports, triage notes).
Installation
npx skills add https://github.com/tsale/awesome-dfir-skills
Stronger alternatives
This repository is archived — consider an actively maintained alternative.
Professional malware analysis workflow for PE executables and suspicious files. Triggers on fil…
73 installsHelp users write, validate, and troubleshoot osquery SQL queries using provided osquery table s…
11 installsAnalyse Mitre ATT&CK tactics, techniques and sub-techniques. Use when performing analysis of th…
11 installsBuild structured threat actor profiles using the 5W1H framework and the Diamond Model. Use this…
7 installsSimilar popular skills
Related neighbors and high-traction skills in the same topics — useful to compare before installing.
Uses the Linux Audit framework (auditd) with ausearch and aureport utilities to detect intrusio…
497 installsParse Apache and Nginx access logs to detect SQL injection attempts, local file inclusion, dire…
394 installsConfigures host-based intrusion detection systems (HIDS) to monitor endpoint file integrity, sy…
118 installsAlso in this package
Other skills from tsale/awesome-dfir-skills.
npx skills add https://github.com/tsale/awesome-dfir-skills
More details
Agent compatibility
Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.
Repository health
main
History
- First recorded snapshot · 4 installs