abusing-dpapi-for-cred…
Extract and decrypt Windows DPAPI-protected secrets (Credential Manager, browser logins/cookies, Wi-Fi credentials, KeePass keys) online or offline using…
Perform comprehensive forensic analysis of raw (dd), E01, or AFF disk images with Autopsy and The Sleuth Kit, recovering deleted files, examining metadata and embedded artifacts, keyword searching, and building investigation timelines with visual reports. Use for structured
$ npx -y skills add mukul975/Anthropic-Cybersecurity-Skills --skill analyzing-disk-image-with-autopsy --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/analyzing-disk-image-with-autopsyContext preview
The summary Claude sees to decide when to auto-load this skill.
Perform comprehensive forensic analysis of raw (dd), E01, or AFF disk images with Autopsy and The Sleuth Kit, recovering deleted files, examining metadata and embedded artifacts, keyword searching, and building investigation timelines with visual reports. Use for structured
name: analyzing-disk-image-with-autopsy description: Perform comprehensive forensic analysis of raw (dd), E01, or AFF disk images with Autopsy and The Sleuth Kit, recovering deleted files, examining metadata and embedded artifacts, keyword searching, and building investigation timelines with visual reports. Use for structured analysis of a forensic disk image or when stakeholders need visual reports from evidence. domain: cybersecurity subdomain: digital-forensics tags: - forensics - autopsy - disk-analysis - sleuth-kit - file-recovery - artifact-analysis version: '1.0' author: mahipal license: Apache-2.0 nist_csf: - RS.AN-03 - DE.AE-02 - RS.MA-01 mitre_attack: - T1005 - T1074.001 - T1070.004 - T1083
# On Linux, install Sleuth Kit and Autopsy sudo apt-get install autopsy sleuthkit # Download Autopsy 4.x (GUI version) from official source wget https://github.com/sleuthkit/autopsy/releases/download/autopsy-4.21.0/autopsy-4.21.0.zip unzip autopsy-4.21.0.zip -d /opt/autopsy # On Windows, run the MSI installer from sleuthkit.org # Launch Autopsy /opt/autopsy/bin/autopsy --nosplash # For Sleuth Kit command-line analysis alongside Autopsy sudo apt-get install sleuthkit
1. Launch Autopsy > "New Case" 2. Enter Case Name: "CASE-2024-001-Workstation" 3. Set Base Directory: /cases/case-2024-001/autopsy/ 4. Enter Case Number, Examiner Name 5. Click "Add Data Source" 6. Select "Disk Image or VM File" 7. Browse to: /cases/case-2024-001/images/evidence.dd 8. Select Time Zone of the original system 9. Configure Ingest Modules (see Step 3)
# Alternatively, use Sleuth Kit CLI to verify the image first img_stat /cases/case-2024-001/images/evidence.dd # List partitions in the image mmls /cases/case-2024-001/images/evidence.dd # Output example: # DOS Partition Table # Offset Sector: 0 # Units are in 512-byte sectors # Slot Start End Length Description # 00: ----- 0000000000 0000002047 0000002048 Primary Table (#0) # 01: 00:00 0000002048 0001026047 0001024000 NTFS (0x07) # 02: 00:01 0001026048 0976771071 0975745024 NTFS (0x07) # List files in a partition (offset 2048 sectors) fls -o 2048 /cases/case-2024-001/images/evidence.dd
Enable the following Autopsy Ingest Modules: - Recent Activity: Extracts browser history, downloads, cookies, bookmarks - Hash Lookup: Compares files against NSRL and known-bad hash sets - File Type Identification: Identifies files by signature, not extension - Keyword Search: Indexes content for full-text searching - Email Parser: Extracts emails from PST, MBOX, EML files - Extension Mismatch Detector: Finds files with wrong extensions - Exif Parser: Extracts metadata from images (GPS, camera, timestamps) - Encryption Detection: Identifies encrypted files and containers - Interesting Files Identifier: Flags files matching custom rule sets - Embedded File Extractor: Extracts files from ZIP, Office docs, PDFs - Picture Analyzer: Categorizes images using PhotoDNA or hash matching - Data Source Integrity: Verifies image hash during ingest
# Configure NSRL hash set for known-good filtering # Download NSRL from https://www.nist.gov/itl/ssd/software-quality-group/national-software-reference-library-nsrl wget https://s3.amazonaws.com/rds.nsrl.nist.gov/RDS/current/rds_modernm.zip unzip rds_modernm.zip -d /opt/autopsy/hashsets/ # Import into Autopsy: # Tools > Options > Hash Sets > Import > Select NSRLFile.txt # Mark as "Known" (to filter out known-good files)
# In Autopsy GUI: Navigate tree structure # - Data Sources > evidence.dd > vol2 (NTFS) # - Examine directory tree, note deleted files (marked with X) # Using Sleuth Kit CLI for targeted recovery # List deleted files fls -rd -o 2048 /cases/case-2024-001/images/evidence.dd # Recover a specific deleted file by inode icat -o 2048 /cases/case-2024-001/images/evidence.dd 14523 > /cases/case-2024-001/recovered/deleted_document.docx # Extract all files from a directory tsk_recover -o 2048 -d /Users/suspect/Documents \ /cases/case-2024-001/images/evidence.dd \ /cases/case-2024-001/recovered/documents/ # Get detailed file metadata istat -o 2048 /cases/case-2024-001/images/evidence.dd 14523 # Shows: creation, modification, access, MFT change timestamps, size, data runs
In Autopsy:
1. Keyword Search panel > "Ad Hoc Keyword Search"
2. Search terms: credit card patterns, SSN regex, email addresses
3. Example regex for credit cards: \b(?:4[0-9]{12}(?:[0-9]{3})?|5[1-5][0-9]{14})\b
4. Example regex for SSN: \b\d{3}-\d{2}-\d{4}\b
5. Review results > Right-click items > "Add Tag"
6. Create tags: "Evidence-Critical", "Evidence-Supporting", "Requires-Review"
7. Add comments to tagged items documenting relevance# Using Sleuth Kit for CLI keyword search srch_strings -a -o 2048 /ca
817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 29 security domains · Apache 2.0
Repo: mukul975/Anthropic-Cybersecurity-Skills
Extract and decrypt Windows DPAPI-protected secrets (Credential Manager, browser logins/cookies, Wi-Fi credentials, KeePass keys) online or offline using…
Take over Active Directory accounts by writing attacker-controlled public keys to msDS-KeyCredentialLink (Shadow Credentials) with pyWhisker, Whisker, or…
Prepare a defense-contractor environment for CMMC Level 2 certification: scope CUI and FCI, implement the 110 NIST SP 800-171 Rev 2 security requirements…
Create forensically sound bit-for-bit disk images with dd or dcfldd on a Linux forensic workstation, preserving evidence integrity through hash verification…
Detect dangerous ACL misconfigurations in Active Directory using ldap3
Perform static analysis of Android APK malware using apktool for resource decompilation, jadx for Java source recovery, and androguard for manifest inspection,…