{"enrichment":{"faq":[{"a":"Incident-response guides evidence collection and analysis during active security breaches across endpoints, memory, logs, and cloud environments. It covers triage acquisition with Velociraptor and KAPE, memory forensics via Volatility 3, Windows event-log timelining with Chainsaw and Hayabusa, anti-forensics detection including timestomping, cloud identity-plane attacks, and ransomware or ESXi hypervisor response.","q":"What is incident-response and what does it cover?"},{"a":"Incident-response enables rapid evidence collection using Velociraptor and KAPE for endpoint triage, Volatility 3 for memory forensics, and Chainsaw/Hayabusa for Windows event-log analysis. These tools work together to reconstruct attack timelines from memory dumps, logs, and artifacts, supporting the primary intent to acquire and analyze evidence from active security incidents.","q":"How does incident-response help acquire and analyze evidence from active incidents?"},{"a":"Yes. Incident-response addresses timestomping detection, log clearing, and other anti-forensics evasion techniques. Tools like Hayabusa and Chainsaw help identify suspicious event-log modifications, while memory forensics with Volatility 3 can reveal process injection and rootkit activity that attackers use to hide their tracks during active breaches.","q":"Can incident-response detect anti-forensics techniques and evidence tampering?"},{"a":"Incident-response includes dedicated ransomware triage and rapid-response playbooks, plus ESXi hypervisor-specific forensics and containment actions. These capabilities enable responders to quickly identify encryption activity, isolate affected systems, and preserve evidence from both traditional endpoints and virtualized infrastructure under active attack.","q":"What incident-response capabilities exist for ransomware and hypervisor attacks?"},{"a":"Incident-response covers cloud IR for AWS and Azure environments, including cloud audit-log investigation and credential-theft detection from identity-plane attacks. It guides responders through analyzing cloud identity events, detecting compromised credentials, and performing containment actions specific to cloud infrastructure during active incidents.","q":"How does incident-response support cloud identity-plane forensics?"},{"a":"Incident-response uses super-timeline creation with Plaso and Timesketch, Windows event-log timelining via Chainsaw and Hayabusa with Sigma rules, and memory forensics via Volatility 3. These techniques correlate artifacts from multiple sources\u2014memory dumps, logs, and endpoint collections\u2014to reconstruct the complete attack timeline from initial compromise through post-exploitation activity.","q":"What tools and techniques does incident-response use for timeline reconstruction?"}],"shadow_tags":["forensic-investigation","threat-containment","memory-analysis","log-timeline","cloud-security","ransomware-response","evidence-preservation","rootkit-detection","identity-compromise"],"summary_rewrite":"Incident Response guides evidence collection and analysis during active security breaches across endpoints, memory, logs, and cloud environments. It covers triage acquisition with Velociraptor and KAPE, memory forensics via Volatility 3, Windows event-log timelining with Chainsaw and Hayabusa, anti-forensics detection including timestomping, cloud identity-plane attacks, and ransomware or ESXi hypervisor response."},"files":[{"bytes":9989,"path":"skills/incident-response/SKILL.md","sha256":"c92d544b72000f405c91292efc728726a2edcebf60822a9a84fc2bfc29ee9794","url":"https://skillfed.io/files/hypnguyen1209/offensive-claude/incident-response/77463ae6/SKILL.md"}],"id":"hypnguyen1209/offensive-claude/incident-response","links":{"html":"https://skillfed.io/hypnguyen1209/offensive-claude/incident-response","md":"https://skillfed.io/hypnguyen1209/offensive-claude/incident-response.md","repo":"https://github.com/hypnguyen1209/offensive-claude"},"meta":{"agents_supported":[],"first_seen":"2026-07-28","forks":58,"language":"Python","last_updated":"2026-07-03","license":"MIT","name":"incident-response","publisher":"hypnguyen1209","stars":326},"relations":{"similar":[{"id":"hypnguyen1209/offensive-claude/threat-hunting"},{"id":"AgentSecOps/SecOpsAgentKit/ir-velociraptor"},{"id":"elementalsouls/Claude-BugHunter/vmware-vcenter-attack"},{"id":"ljagiello/ctf-skills/ctf-forensics"},{"id":"Azarisa0678/DevSecOpsSkill1/DevSecOpsSkill1"},{"id":"Aradotso/security-skills/malware-detection-warning"},{"id":"Aradotso/security-skills/security-awareness-malicious-repository-detection"},{"id":"hypnguyen1209/offensive-claude/malware-analysis"},{"id":"Aradotso/security-skills/malware-detection-security-awareness"},{"id":"Aradotso/devtools-skills/meccha-chameleon-game-cheat-detection"}]},"slug":{"owner":"hypnguyen1209","repo":"offensive-claude","skill":"incident-response"},"version":"77463ae6"}
