eni-malware-ir-workflow

SkillDocs & knowledge

[DOCUMENTATION ONLY] [仅文档] Offline malware triage, capability analysis, memory forensics, timeline, IOC packaging, and incident-response workflow.

Available today. Use it from your connected AI after setup.

Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.

Then ask your AI: use the eni-malware-ir-workflow skill

What this skill tells your AI

The instructions your AI receives, as published by alicewe1/alice_skill in _modules/eni-malware-ir-workflow/SKILL.md and read by ahel’s review.

仅文档:本 Skill 提供方法与检查表,不宣称自带可执行脚本。

Malware IR Workflow

Hash and preserve samples. Use capability-first triage, static reverse analysis, and Volatility-style memory context. Separate observed facts from hypotheses. Build a timeline, IOC package, confidence labels, and verification notes.

Persist checkpoints before long runs. Record commands, versions, hashes, evidence paths, assumptions, and verification results. Chain through eni-universal-workflow and finish with delivery.

Signals

GitHub stars
26
Forks
4
Last commit
Sep 2026
Advanced
Item type
skill
Key
eni-malware-ir-workflow
Source
github.com/alicewe1/alice_skill