Claude Code Skills·Claude Skills·The open SKILL.md registry for Claude
ClaudSkillsSecurity › Forensics › Page 2

Forensics (Page 2 of 5)

295 Claude Code skills in the Forensics sub-category of Security.

295 skills · updated 2026-08-26 · showing 61–120 of 295 by quality score

For the full experience including quality scoring and one-click install features for each skill — upgrade to Pro.

On-chain analysis and transaction forensics for blockchain security investigations. Provides capabilities for tracing fund flows, identifying suspicious patterns, MEV analysis,…
Festlandchina Wirtschaftsverkehr: Evidence Preservation China. Geführter Spezialskill mit Quellenlogik, Prüfroutine, Red-Team-Fragen und verwertbarem Output.
Publishes structured, actionable artifacts from Claude Code sessions — PR walkthroughs, incident timelines, system explainers, release checklists, and security audits.
Security audit and threat model for OpenClaw gateway hosts. Use to verify OpenClaw configuration, exposure, skills/plugins, filesystem hygiene, and to produce an OK/VULNE — from…
Security audit and threat model for OpenClaw gateway hosts. Use to verify OpenClaw configuration, exposure, skills/plugins, filesystem hygiene, and to produce an OK/VULNE — from…
Review an exact code change for correctness, regressions, security, compatibility, test quality, and maintainability using the diff and repository evidence.
GLAW Master Command — the top-level intelligence-fusion orchestrator. Coordinates the FBI bureau, FinCEN financial-intelligence cell, CIA strategic-intelligence cell, SEC…
Internal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for DFIR chronology, cross-artifact correlation, persistence chains, and incident timeline re — from…
Configures Windows Event Logging with advanced audit policies to generate high-fidelity security events for
Contain a suspected or confirmed macOS threat and verify recovery. Use when a Mac may need network isolation, process or service containment, account and credential response,…
Contain an active or credible cybersecurity incident across hosts, identities, applications, services, cloud resources, networks, or data.
Docker, containerd/CRI-O, and Kubernetes forensic investigation covering container inventory (docker and crictl), privilege checks, image verification, layer analysis (dive),…
Review local PRs and high-risk local diffs through independent fresh-context reviewers and a root-verified evidence ledger.
Verifies provider credentials via NPI MCP, searches Medicare coverage policies via CMS Coverage MCP, and maps clinical evidence against payer policy requirements with…
Use when the user faces a PR crisis or reputational threat and needs rapid severity assessment, stakeholder messaging, and a communication timeline.
Write a structured escalation brief for an at-risk customer account. Use when an account has escalated, when a customer is threatening churn, when a P1 customer issue needs…
Digital forensics and blockchain analysis for CTF challenges. Use when analyzing disk images, memory dumps, event logs, network captures, or cryptocurrency transactions.
Default entrypoint and master ctf-sandbox-orchestrator workflow for CTF, exploit, reverse engineering, DFIR, pwnable, crypto, stego, mobile, AI-agent, cloud, container, Active…
Compliance and security auditing for Cursor IDE usage: SOC 2, GDPR, HIPAA assessment, evidence collection, and remediation.
Resolve or audit one customer-support case from verified facts through a humane response, remedy or compensation, protected-action handoff, legal or abuse escalation, follow-up,…
Run and interpret CyberEdge's reviewed, bounded Nuclei vulnerability baseline for an explicitly authorized Scope.
Produces structured cybersecurity breach summary documents for regulatory and compliance use. Use when drafting breach summaries, incident response reports, forensic report…
Cybersecurity senior. Pentesting, red team, blue team, threat intel, compliance, forensics.
Use when starting any cybersecurity task — master router that determines the testing phase (Recon/Validation/Exploitation/Post-Exploitation) and routes to the correct specialized…
Review Dynamics 365 Finance & Operations security role design, duty and privilege assignments, segregation of duties (SoD) conflict rules, user-role assignments, and audit…
Data modeling and safe-migrations guide, agnostic of engine (relational and non-relational). worktree-agent-data MUST apply it when designing/implementing, classifying each…
A final accuracy check for security work — it re-tests a conclusion against the evidence and labels each part as confirmed, inferred, or assumed, so an unverified result never…
Blue-team release-gate analysis for smart contract deployment and upgrade readiness. Classifies repositories, checks deploy/upgrade execution paths, CI/CD trust boundaries, config…
Analyze a specific dependency upgrade using manifests, lockfiles, repository usage, and verified official release evidence, including breaking changes, runtime requirements,…
Use when the deliverable is a DESCRIPTION of what's in the data rather than an effect, a counterfactual, or a prediction — stylized facts, raw and indexed trends ("what's the…
Build retention into visit burden, schedule, and engagement to lower the ~30% dropout, instead of re-recruiting. Reach for this when dropout threatens the timeline.
Digital forensics and incident response - Windows event log analysis, PCAP forensics, filesystem artifact analysis, AD attack detection, and timeline correlation.
Use when a project needs DFIR readiness from the security-engineering side: prepare incident evidence handling, chain-of-custody expectations, IOC readiness, and handoff to…
Analyze disk images and file systems for forensic investigation. Use when investigating data theft, insider threats, malware persistence, deleted file recovery, or any incident…
Use when an Economic Policy (EP) manuscript's results may be specification-, sample-, or inference-fragile, especially ahead of the two-discussant panel.
Use to red-team an Econometrica manuscript before submission and to anticipate co-editor and referee objections — proof gaps, generality, missing finite-sample evidence, and…
Analyze email messages and mailbox data for forensic investigation. Use when investigating phishing attacks, business email compromise, insider threats, or any scenario requiring…
EU NIS2 Directive (Directive (EU) 2022/2555) expert. Reference-depth knowledge of essential vs important entity classification, Article 20 governance, the Article 21 ten…
Use when targeting European Symposium on Research in Computer Security (ESORICS) or deciding whether a computer-science manuscript fits this venue.
Normalize and correlate evidence across UI, API, security scans, and logs into a causal chain explanation and unified evidence bundle.
Evidence-capture and PoC-redaction discipline for bug-bounty submissions: cookie redaction protocol (which fields to mask, Preview annotation / Burp panel hiding / DevTools…
Orchestrate evidence-gated AI software delivery from an ambiguous request through product framing, implementation, verification, operational safety, and durable closeout.
Dispatches `forge-expert` subagents in parallel — one per chosen domain — to produce focused analyses of a feature against the codebase before a plan is drafted.
Extract cached credentials, password hashes, Kerberos tickets, and authentication tokens from memory dumps using
Create, edit, or triage evidence-rich GitHub issues under each repository's rules. Use for issue drafts or filing, confirmed defects, scoped feature requests, duplicate searches,…
Use when targeting Financial Cryptography and Data Security (FC) or deciding whether a computer-science manuscript fits this venue.
GLAW FinCEN Cell — Chief Financial Intelligence Officer (CFIO). Directs financial-crime investigations: runs the SAR, AML, OFAC-sanctions, crypto/blockchain, and…
Turns a startup URL, repo, or product idea into a qualified, evidence-backed shortlist of potential first customers using recent PUBLIC signals only -- demand, pain, workaround,…
Framework for designing token economics for Flow-based protocols. Covers economic first principles (Fisher Equation MV=PQ, Nash equilibrium, mechanism design, behavioral…
Wirtschaftsprüfer: forensic services und unabhaengigkeit - Rechtsprechungscheck, stärkste Gegenansicht und Red-Team-Korrektur; mit Live-Normencheck, Kammerlogik,…
Use whois in Forensic Claw for lawful DFIR, cyber security, evidence triage, intrusion analysis, and case-backed forensic workflows.
Forensics Data Collector - Auto-activating skill for Security Advanced. Triggers on: forensics data collector, forensics data collector Part of the Security Advanced skill…
SQL-powered forensic investigation and system interrogation using osquery to query operating systems as relational databases.
AUTO-INVOKE when user mentions forensics, incident response, IOC, log analysis, evidence preservation, breach investigation, threat hunting, attack timeline.
Analyze network traffic and security incidents with the depth of an "Ultimate Forensics Team". Emphasizes deep packet analysis (PCAP) as the source of truth, OSI layer…
Performs a white-box security review of Atlassian Forge apps using structured, Forge-specific security rules and evidence-driven reporting.
Use when revising an ESEC/FSE paper for a practitioner-grounded software-engineering contribution on the first page, research-question contracts, a threats-to-validity section…
Run Hayabusa against collected Windows EVTX files to apply Sigma detection rules and produce a prioritized, chronological CSV/JSON timeline with severity levels, MITRE ATT&CK…
Geschäftsgeheimnisschutz in China-Operationen: Chinesisches UWG (Anti-Unfair Competition Law) und Trade-Secret-Definitionen, GeschGehG (DE) §§ 2 ff.
End-to-end engineering workflow for Ghayth and similar business systems. Use to plan, build, fix, refactor, test, review, secure, optimize, monitor, release, or merge code…
All Security skills →
More in SecurityRed Team (1,582) · Web Security (1,094) · Threat Hunting (754) · Identity Access (496) · Network Security (414) · Appsec Tools (381) · Malware Analysis (207) · Compliance (204) · Cloud Security (94) · Zero Trust (82) · Appsec Build (66) · Crypto Keymgmt (65) · Incident Response (20) · Ot Ics Security (9)