DFIR triage & investigation
SkillMonitoring & opsFirst-response DFIR triage: scope an incident, collect volatile evidence, and find attacker activity on Linux/Windows. Load on "incident", "we got breached", "investigate this host", "IOCs", suspected compromise, or forensic triage. Signals: alert to investigate, suspicious host, "what happened".
Instructions available. Your AI can read the instructions. Execution depends on the setup they require.
Account requirements not reviewed. Check the skill instructions before use; ahel provides instructions and does not run this skill.
Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
Then ask your AI: use the DFIR triage & investigation skill
What this skill tells your AI
The instructions your AI receives, as published by noorqureshi/sploitagent in skills/defense/defense-dfir-triage/SKILL.md and read by ahel’s review.
When it applies
A host or account is suspected compromised and you need to determine what happened, scope it, and preserve evidence — quickly, without destroying volatile data.
Why it works
Attacker activity leaves artifacts across a known set of locations (execution, persistence, logons, network). A disciplined order — preserve volatile first, then map to ATT&CK — gives a timeline and scope instead of a guess.
Method
- Preserve volatile first (order of volatility): memory (if warranted), then running processes, network connections, logged-on users — before shutdown/changes.
- Establish the timeline: parse Windows event logs (
chainsaw/hayabusawith Sigma) or Linux logs/auth; look for initial access, execution, and lateral movement times. - Check the usual artifacts:
- Execution: prefetch/shimcache/amcache (Win), bash history/
/var/log(Linux), scheduled tasks/cron. - Persistence: services, run keys, WMI, startup, cron, systemd units, SSH keys.
- Accounts/logons: new users, 4624/4625, sudo, privilege changes.
- Network: current connections, DNS, beaconing patterns.
- Execution: prefetch/shimcache/amcache (Win), bash history/
- Collect at scale with Velociraptor (hunts across hosts) to scope beyond one machine.
- Map findings to ATT&CK, extract IOCs, and hand detections to
defense-detection-sigma.
Gotchas
- Don't reboot/"clean" before capturing volatile evidence — you'll lose the memory/process picture.
- Correlate timestamps across sources (watch timezones/clock skew) to build a real timeline.
- Scope before remediating: one host is rarely the whole incident — hunt the IOCs fleet-wide.
Verify success
A timeline of attacker actions with initial access, persistence, and scope identified, plus IOCs and mapped ATT&CK techniques ready for detection/containment.
References
SANS DFIR posters; Velociraptor docs; chainsaw/hayabusa; MITRE ATT&CK.
Signals
- GitHub stars
- 20
- Forks
- 7
- Last commit
- Sep 2026
Advanced
- Item type
- skill
- Key
defense-dfir-triage- Source
- github.com/noorqureshi/sploitagent
github.com/noorqureshi/sploitagent
More in Monitoring & ops
Skill · anthropics
More in Monitoring & opsagent-eval
Skill · affaan-m
More in Monitoring & opsarchitecture-decision-records
Skill · affaan-m
More in Monitoring & opsbabysit
Skill · thedotmack
More in Monitoring & opseng-runbook
Skill · nexu-io
More in Monitoring & opsweekly-update
Skill · nexu-io
More in Monitoring & ops