linux-forensics
CommunityInvestigate Linux systems for security incidents.
Authorjmagly
Version1.0.0
Installs0
System Documentation
What problem does it solve?
This Skill automates the process of gathering forensic evidence from Linux systems, ensuring comprehensive and consistent data collection across different distribution families.
Core Features & Use Cases
- Distribution-Aware Collection: Automatically detects and adapts to Debian/Ubuntu, RHEL/CentOS/Rocky, and SUSE families.
- System Integrity Verification: Checks for modified system binaries and configuration files.
- Evidence Gathering: Collects logs, scheduled tasks, persistence mechanisms, network state, and kernel information.
- Use Case: When a Linux server shows signs of compromise, this skill can be triggered to perform a rapid, structured forensic analysis, producing a findings report aligned with NIST guidelines.
Quick Start
Run the linux forensics skill to investigate the remote host api-prod-01.example.com.
Dependency Matrix
Required Modules
None requiredComponents
scriptsreferences
💻 Claude Code Installation
Recommended: Let Claude install automatically. Simply copy and paste the text below to Claude Code.
Please help me install this Skill: Name: linux-forensics Download link: https://github.com/jmagly/aiwg/archive/main.zip#linux-forensics Please download this .zip file, extract it, and install it in the .claude/skills/ directory.
Agent Skills Search Helper
Install a tiny helper to your Agent, search and equip skill from 223,000+ vetted skills library on demand.