acquiring-disk-image-w…
Create forensically sound bit-for-bit disk images using dd and dcfldd while preserving evidence integrity through
Perform comprehensive forensic analysis of disk images using Autopsy to recover files, examine artifacts, and
$ npx -y skills add Mikaru0Mystic/sectinel --skill analyzing-disk-image-with-autopsy --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/analyzing-disk-image-with-autopsyContext preview
The summary Claude sees to decide when to auto-load this skill.
Perform comprehensive forensic analysis of disk images using Autopsy to recover files, examine artifacts, and
name: analyzing-disk-image-with-autopsy description: Perform comprehensive forensic analysis of disk images using Autopsy to recover files, examine artifacts, and build investigation timelines. domain: cybersecurity subdomain: digital-forensics tags: - forensics - autopsy - disk-analysis - sleuth-kit - file-recovery - artifact-analysis version: '1.0' author: mahipal license: Apache-2.0 nist_csf: - RS.AN-01 - RS.AN-03 - DE.AE-02 - RS.MA-01
# On Linux, install Sleuth Kit and Autopsy sudo apt-get install autopsy sleuthkit # Download Autopsy 4.x (GUI version) from official source wget https://github.com/sleuthkit/autopsy/releases/download/autopsy-4.21.0/autopsy-4.21.0.zip unzip autopsy-4.21.0.zip -d /opt/autopsy # On Windows, run the MSI installer from sleuthkit.org # Launch Autopsy /opt/autopsy/bin/autopsy --nosplash # For Sleuth Kit command-line analysis alongside Autopsy sudo apt-get install sleuthkit
1. Launch Autopsy > "New Case" 2. Enter Case Name: "CASE-2024-001-Workstation" 3. Set Base Directory: /cases/case-2024-001/autopsy/ 4. Enter Case Number, Examiner Name 5. Click "Add Data Source" 6. Select "Disk Image or VM File" 7. Browse to: /cases/case-2024-001/images/evidence.dd 8. Select Time Zone of the original system 9. Configure Ingest Modules (see Step 3)
# Alternatively, use Sleuth Kit CLI to verify the image first img_stat /cases/case-2024-001/images/evidence.dd # List partitions in the image mmls /cases/case-2024-001/images/evidence.dd # Output example: # DOS Partition Table # Offset Sector: 0 # Units are in 512-byte sectors # Slot Start End Length Description # 00: ----- 0000000000 0000002047 0000002048 Primary Table (#0) # 01: 00:00 0000002048 0001026047 0001024000 NTFS (0x07) # 02: 00:01 0001026048 0976771071 0975745024 NTFS (0x07) # List files in a partition (offset 2048 sectors) fls -o 2048 /cases/case-2024-001/images/evidence.dd
Enable the following Autopsy Ingest Modules: - Recent Activity: Extracts browser history, downloads, cookies, bookmarks - Hash Lookup: Compares files against NSRL and known-bad hash sets - File Type Identification: Identifies files by signature, not extension - Keyword Search: Indexes content for full-text searching - Email Parser: Extracts emails from PST, MBOX, EML files - Extension Mismatch Detector: Finds files with wrong extensions - Exif Parser: Extracts metadata from images (GPS, camera, timestamps) - Encryption Detection: Identifies encrypted files and containers - Interesting Files Identifier: Flags files matching custom rule sets - Embedded File Extractor: Extracts files from ZIP, Office docs, PDFs - Picture Analyzer: Categorizes images using PhotoDNA or hash matching - Data Source Integrity: Verifies image hash during ingest
# Configure NSRL hash set for known-good filtering # Download NSRL from https://www.nist.gov/itl/ssd/software-quality-group/national-software-reference-library-nsrl wget https://s3.amazonaws.com/rds.nsrl.nist.gov/RDS/current/rds_modernm.zip unzip rds_modernm.zip -d /opt/autopsy/hashsets/ # Import into Autopsy: # Tools > Options > Hash Sets > Import > Select NSRLFile.txt # Mark as "Known" (to filter out known-good files)
# In Autopsy GUI: Navigate tree structure # - Data Sources > evidence.dd > vol2 (NTFS) # - Examine directory tree, note deleted files (marked with X) # Using Sleuth Kit CLI for targeted recovery # List deleted files fls -rd -o 2048 /cases/case-2024-001/images/evidence.dd # Recover a specific deleted file by inode icat -o 2048 /cases/case-2024-001/images/evidence.dd 14523 > /cases/case-2024-001/recovered/deleted_document.docx # Extract all files from a directory tsk_recover -o 2048 -d /Users/suspect/Documents \ /cases/case-2024-001/images/evidence.dd \ /cases/case-2024-001/recovered/documents/ # Get detailed file metadata istat -o 2048 /cases/case-2024-001/images/evidence.dd 14523 # Shows: creation, modification, access, MFT change timestamps, size, data runs
In Autopsy:
1. Keyword Search panel > "Ad Hoc Keyword Search"
2. Search terms: credit card patterns, SSN regex, email addresses
3. Example regex for credit cards: \b(?:4[0-9]{12}(?:[0-9]{3})?|5[1-5][0-9]{14})\b
4. Example regex for SSN: \b\d{3}-\d{2}-\d{4}\b
5. Review results > Right-click items > "Add Tag"
6. Create tags: "Evidence-Critical", "Evidence-Supporting", "Requires-Review"
7. Add comments to tagged items documenting relevance# Using Sleuth Kit for CLI keyword search srch_strings -a -o 2048 /cases/case-2024-001/images/evidence.dd | \ grep -iE '(password|secret|confidential)' > /cases/case-2024-001/keyword_hits.txt # Search for specific file signatures sigfind -o 2048 /cases/case-2024-001/images/evidence.dd 25504446 # 25504446 = %PDF header signature
Open-source security arsenal for AI coding agents: 784 cybersecurity skills, scanner integrations, and a security MCP for Claude Code, Cursor, opencode, Gemini CLI, Cline, and any agentskills.io agent. Mapped to OWASP, MITRE ATT&CK, NIST CSF, D3FEND, ATLAS.
Repo: Mikaru0Mystic/sectinel
Create forensically sound bit-for-bit disk images using dd and dcfldd while preserving evidence integrity through
Detect dangerous ACL misconfigurations in Active Directory using ldap3 to identify GenericAll, WriteDACL, and
Perform static analysis of Android APK malware samples using apktool for decompilation, jadx for Java source
Parses API Gateway access logs (AWS API Gateway, Kong, Nginx) to detect BOLA/IDOR attacks, rate limit bypass,
Analyze advanced persistent threat (APT) group techniques using MITRE ATT&CK Navigator to create layered heatmaps
Queries Azure Monitor activity logs and sign-in logs via azure-monitor-query to detect suspicious administrative