Initial incident intake & scoping
openbooklet.com/s/initial-incident-intake--scopingopenbooklet.com/s/initial-incident-intake--scoping@1.0.0GET /api/v1/skills/initial-incident-intake--scopingFirst-hour intake checklist + questions that produce an actionable scope and evidence plan.
Analyse Mitre ATT&CK tactics, techniques and sub-techniques. Use when performing analysis of threat detections, threat models, security risks or cyber threat intelligence
Professional malware analysis workflow for PE executables and suspicious files. Triggers on file uploads with requests like "analyze this malware", "analyze this sample", "what does this executable do", "check this file for malware", or any request to examine suspicious files. Performs static analysis, threat intelligence triage, behavioral inference, and produces analyst-grade reports with reasoned conclusions.
Help users write, validate, and troubleshoot osquery SQL queries using provided osquery table schemas as the authoritative source.
Auto-indexed from tsale/awesome-dfir-skills
Are you the author? Claim this skill to take ownership and manage it.