Claude Code Skills·Claude Skills·The open SKILL.md registry for Claude
ClaudSkillsSecurity › Forensics › Page 3

Forensics (Page 3 of 4)

200 Claude Code skills in the Forensics sub-category of Security.

200 skills · updated 2026-07-27 · showing 121–180 of 200 by quality score

For the full experience including quality scoring and one-click install features for each skill — upgrade to Pro.

Analyze system, application, and security logs for forensic investigation. Use when investigating security incidents, insider threats, system compromises, or any scenario…
Investigate Salesforce login activity using LoginHistory, IdentityVerificationHistory, and Login Forensics (Event Monitoring add-on): reconstruct per-user login timelines,…
Run adversarial review. Use for PR/diff/code/security/UX/API/performance/design review, or when behavior, records, evidence, risks, or acceptance claims need pressure-testing…
Route security-sensitive work before implementation. Use when authentication, authorization, user input, secrets, sensitive data, uploads, webhooks, external integrations,…
Build and run a third-party / vendor risk management (TPRM) program aligned to NIST SP 800-161 C-SCRM and NIST CSF 2.0 GV.SC: inventory and tier vendors by risk, send the right…
Use when administering a Synapse / Matrix homeserver — list or snapshot all rooms, rate room health (public, unencrypted, orphaned), render a Graphviz map of the room/space tree,…
Comprehensive techniques for acquiring, analyzing, and extracting artifacts from memory dumps for incident response and malware analysis.
Use when Mission Control should recommend a read-only handoff audit burst for run instructions, validation evidence, limitations, docs quality, and security caveats.
Prepare a project for release through Mission Control. Use when validation, docs, versioning, changelog, limitations, evidence, deployment readiness, and security concerns need…
Mobile device intelligence — Android/iOS app analysis, mobile forensics, emulators, messaging app reconnaissance, and device fingerprinting.
Use when targeting Network and Distributed System Security Symposium (NDSS) or deciding whether a computer-science manuscript fits this venue.
Analyze network traffic for defensive triage and operate the local defense-focused plugin runtime for PCAP forensics, live capture review, incident prioritization, posture…
Assess non-functional requirements across 6 quality categories (Security, Performance, Reliability, Maintainability, Scalability, Usability) with measurable criteria,…
EU NIS2 Directive (Directive (EU) 2022/2555) compliance advisor for essential and important entities — entity classification, Art. 21 risk management measures, Art.
Generate a NIST Cybersecurity Framework (CSF) 2.0 compliance report — interactively walks through every function, category, and subcategory, collecting evidence and pulling…
Run an office move or reconfiguration without losing a week of work — the dependency-ordered plan (internet lead times rule everything), the workstream owners, the comms that keep…
Simulates the opposing party's litigation and negotiation strategy by mapping their likely factual narrative, categorizing defenses, predicting evidence attacks, and designing…
Operational security management — traffic shaping, scan rate limiting, source IP management, tool signature avoidance, evidence handling, anti-detection patterns.
OSINT Investigator v2.1 — comprehensive open-source intelligence skill. Triggers on: OSINT, recon, digital footprint, dorking, social media investigation, username lookups, email…
GRIMSEC Agent 11: Evidence-backed forensic investigation of open-source GitHub repositories. Use when investigating supply chain incidents, suspicious commits, compromised…
Digital forensics — evidence acquisition, memory/disk imaging analiz, timeline reconstruction, IOC extraction advisory.
Operator OPSEC + evidence handling — operator identity hygiene, source IP design, burner infrastructure, evidence chain of custody, log retention advisory.
Uses Falco YAML rules for runtime threat detection in containers and Kubernetes, monitoring syscalls for shell
Perform forensic acquisition and analysis of cloud storage services including Google Drive, OneDrive, Dropbox,
Collect, parse, and correlate system, application, and security logs to reconstruct events and establish timelines
Use when scanning an external macro environment with PESTEL/PESTLE (and its variant family STEEPLE, STEEPLED, PESTLIED, STEEP, DESTEP, LoNGPESTLE): political, economic, social,…
Use after PNAS reviews arrive to triage the decision, prioritize experiments, and draft a point-by-point response that is respectful, evidence-led, and honest about limits.
Create or refine promptfoo redteam setup configs: purpose, targets, plugins, strategies, frameworks, multi-input target inputs, policy text, grader guidance, contexts, and…
Reusable writing-style contract for agent outputs (reports, ARCH docs, verdicts, threat models). Forces direct prose with concrete evidence, no marketing voice, no hedge words.
Configure Cedar policy enforcement and Ed25519 signed receipts for Claude Code tool calls. Use when setting up projects that need cryptographic audit trails, policy-gated tool…
AI red-teaming framework for testing LLMs and generative AI systems for jailbreaks, prompt injection, harmful content, data leakage, and multi-turn attacks.
Use when reviewing, designing, or modifying Java enterprise systems that may support essential or important entities, critical-sector services, managed service providers — from…
Resolve the material product, behavior, compatibility, data, permission, security, migration, and acceptance decisions that remain open before specification or implementation.
Use for recurring backup-restore validation and disaster-recovery simulation, including restore runbooks, drill frequency, pass/fail gates, evidence capture, and remediation…
RAPTOR turns Claude Code into an evidence-first offensive and defensive security research workflow for mapping attack surfaces, validating scanner findings, analyzing binaries,…
Use to build or instrument a Sail Voyage — Sail's name for one background or long-running agent run, recorded as a trace of named agents, spans, and events.
Package and structure audit evidence for SAP controls covering Segregation of Duties, change management, access management, and financial controls.
SAP BTP best practices for enterprise architecture, account management, security, and operations, with verification evidence tracked in the repository ledger.
Enumerate and export SAP BTP and S/4HANA landscape configuration using read-only list, get, describe, and export operations only.
Plan and remediate dependency vulnerabilities with Endor SCA findings, VersionUpgrade/UIA evidence, separate low-risk PR lanes, deterministic risk decisions, local validation, and…
Get your security deposit back — the move-out documentation that wins disputes before they start, the itemized-deduction challenge, the demand-letter ladder, and the small-claims…
Generate the quarterly macOS security-compliance evidence screenshot package for Nathan. Use when asked to create/recreate the evidence zip (e.g.
Creates response procedures for security incidents with containment steps, communication templates, and evidence collection.
Generate UI for .NET MAUI (Shiny.Maui.Controls) and Blazor (Shiny.Blazor.Controls) - includes TableView with 14 cell types, TreeView with lazy loading, drag/drop reorder…
Use when reviewing vulnerability reports, reproduction notes, scanner tickets, submission drafts, audit findings, or claimed technical_confirmed vulnerabilities for evidence…
Use when planning, coordinating, or reviewing evidence-first security code audits, vulnerability hunting, scanner triage, exploitability review, or report verification across a…
Comprehensive security audit with evidence-based findings. Combines deep pattern knowledge with contextual reasoning to eliminate false positives.
US stocks analysis by an adversarial investment committee. Legendary-investor personas independently research a thesis, attack each other's cases against a shared evidence ledger…
Use when turning internal/external situation analysis into strategic options with SWOT and TOWS: strengths, weaknesses, opportunities, threats, evidence quality, SO/WO/ST/WT…
Manage Tencent Cloud EdgeOne (CDN + edge security). Use when the user asks to: list zones, purge CDN cache (URL / prefix / hostname / all), prefetch URLs to warm edges, check…
Use any time someone asks for a thermonuclear review or a thorough/intense code review of a PR or some changes.
Search and retrieve clinical practice guidelines across 12+ authoritative sources including NICE, WHO, ADA, AHA/ACC, NCCN, SIGN, CPIC, CMA, CTFPHC, GIN, MAGICapp, PubMed,…
Draft a professional Hebrew letter for an Israeli traffic-ticket appeal — בקשה לביטול דו"ח or בקשה להישפט. Respectful tone, factual claims only, evidence list, requested remedy.
Guide live digital-forensics and incident-response work with human approval gates when the job is evidence review and triage, not general MCP setup.
Drafts Evidence of UCC Lien Release documents proving termination of security interests perfected under the Uniform Commercial Code.
FINRA Broker-Dealer Cybersecurity Guidance expert. Stub-depth framework plugin that routes to the SCF crosswalk.
Prüft Software als Trade Secret nach US-Recht: secrecy measures, misappropriation, employee mobility und repository evidence im Softwarerecht De Eu Us.
Use when targeting USENIX Security Symposium (USENIX Security) or deciding whether a computer-science manuscript fits this venue.
15-agent hierarchical mesh coordination for v3 implementation. Orchestrates parallel execution across security, core, and integration domains following 10 ADRs with 14-week…
Run a third-party / vendor security review and assign a risk tier with required controls. Use when asked to assess a vendor's security, run a third-party risk assessment, complete…
All Security skills →
More in SecurityRed Team (1,515) · Web Security (939) · Threat Hunting (588) · Identity Access (420) · Network Security (357) · Appsec Tools (333) · Compliance (191) · Malware Analysis (175) · Cloud Security (83) · Zero Trust (68) · Appsec Build (61) · Crypto Keymgmt (53) · Incident Response (18) · Ot Ics Security (7)