BigHugger
sk Skill · mukul975

collecting-volatile-evidence-from-compromised-host

Collect volatile forensic evidence from a compromised host by following the order of volatility, preserving memory, network connections, running processes, and system state with documented chain of custody before they are lost. Use before isolating, shutting down, or remediating a compromised host, especially when fileless or memory-resident malware is suspected, root cause analysis is needed, or the evidence must…

installs 8w
0
30-day movement
starts with the next reading
Related entries
1
Connections
0
chain-of-custodybashmemory-forensicsvolatile-evidencePythonforensicsdfirincident-response
Host repository
mukul975/Anthropic-Cybersecurity-Skills
Version
1.0
Licence
Apache-2.0
Host stars
33k
Host language
Python