# Examples of Digital Forensics Skills in the Anthropic Cybersecurity Skills Repository

> Explore Digital Forensics skills in the Anthropic Cybersecurity Skills repository. Discover examples of automated tasks like memory analysis, artifact parsing, and timeline reconstruction.

- Repository: [Mahipal/Anthropic-Cybersecurity-Skills](https://github.com/mukul975/Anthropic-Cybersecurity-Skills)
- Tags: deep-dive
- Published: 2026-05-24

---

**The Anthropic Cybersecurity Skills repository hosts approximately 40 Digital Forensics skills organized under the `digital-forensics` subdomain, each providing executable automation for tasks like volatile memory analysis, Windows artifact parsing, and timeline reconstruction.**

The `mukul975/Anthropic-Cybersecurity-Skills` repository structures cybersecurity capabilities as discrete, reusable units. Every Digital Forensics skill resides in a dedicated folder under `skills/` and contains executable Python agents, metadata specifications, and reference documentation that enable automated forensic investigation workflows.

## Repository Structure for Digital Forensics Skills

The repository identifies Digital Forensics capabilities through a standardized metadata scheme. Each skill directory contains a [`SKILL.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/SKILL.md) file that declares `subdomain: digital-forensics` in its YAML-style header, establishing the skill's domain classification.

All skills follow a uniform architecture:

- **[`SKILL.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/SKILL.md)** — The human-readable specification containing the skill name, description, prerequisites, and detailed workflow steps
- **[`scripts/agent.py`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/scripts/agent.py)** or **[`scripts/process.py`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/scripts/process.py)** — Executable automation that orchestrates forensic tools (Volatility 3, KAPE, Plaso, Wireshark) and generates structured output
- **`references/`** — Supporting documentation citing external standards (SANS, NIST CSF) and tool manuals
- **`assets/`** — Optional templates including JSON schemas, CSV formats, or PowerShell scripts
- **`LICENSE`** and **`README`** — Legal and high-level overview files

This consistency allows security practitioners to browse the repository, locate a relevant forensic capability, and execute the workflow via command line without manual configuration.

## Key Digital Forensics Skills Examples

The repository covers the full forensic investigation lifecycle, from volatile memory acquisition to mobile device analysis.

### Memory and System Analysis

**`performing-memory-forensics-with-volatility3`** automates volatile memory analysis using the Volatility 3 framework. The skill's [`scripts/agent.py`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/scripts/agent.py) executes process listing, malfind scans, network connection extraction, and optional YARA rule matching against raw memory dumps.

**`performing-windows-artifact-analysis-with-eric-zimmerman-tools`** integrates KAPE (Kroll Artifact Parser and Extractor) with Eric Zimmerman's EZ Tools to parse MFT entries, registry hives, Prefetch files, LNK shortcuts, and Windows Event Logs.

### Timeline and Network Reconstruction

**`performing-timeline-reconstruction-with-plaso`** generates super-timelines from disk images using Plaso (log2timeline). The automation exports data to CSV/JSON formats compatible with Timesketch for collaborative visualization.

**`performing-network-forensics-with-wireshark`** leverages Wireshark and tshark to capture, filter, and extract evidence from PCAP files, extracting metadata and reassembled session data.

### Specialized Artifact Parsing

**`analyzing-mft-for-deleted-file-recovery`** carves deleted file entries from the Master File Table and produces detailed CSV reports for file recovery operations.

**`analyzing-windows-shellbag-artifacts`** parses Shellbag Registry entries to reconstruct historical folder browsing activity and user navigation patterns.

**`analyzing-windows-prefetch-with-python`** extracts execution timestamps and run counts from Prefetch files using custom Python parsers.

**`performing-sqlite-database-forensics`** recovers deleted records, parses Write-Ahead Log (WAL) files, and extracts browser history from SQLite databases common to mobile and desktop applications.

### Mobile and Disk Imaging

**`analyzing-disk-image-with-autopsy`** drives an Autopsy instance to automatically ingest raw or E01 disk images and generate forensic artifacts without manual GUI interaction.

**`analyzing-android-malware-with-apktool`** decompiles Android APK files, extracts embedded payloads, and performs static analysis to identify malicious code patterns.

## Executing Digital Forensics Skills

Each skill provides ready-to-run automation scripts. Below are practical execution examples for two core capabilities.

### Volatile Memory Analysis with Volatility 3

Navigate to the memory forensics skill directory and invoke the agent against a memory dump:

```bash
cd skills/performing-memory-forensics-with-volatility3

python3 -m pip install volatility3

./scripts/agent.py /cases/example/memory.raw ./output

```

To include malware detection, pass a YARA rule file as an optional third argument:

```bash
./scripts/agent.py /cases/example/memory.raw ./output /opt/rules/malware.yar

```

The script generates [`output/memory_forensics_report.json`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/output/memory_forensics_report.json) containing operating system information, process listings, hidden-process detection results, network connection tables, extracted hashes, and YARA match results.

### Super-Timeline Generation with Plaso

From the Plaso skill directory, install the required tools and process evidence:

```bash
cd skills/performing-timeline-reconstruction-with-plaso

sudo add-apt-repository ppa:gift/stable
sudo apt-get update && sudo apt-get install plaso-tools

log2timeline.py \
  --storage-file ./timeline/evidence.plaso \
  /cases/example/evidence.dd

```

Export the timeline to CSV format for analysis:

```bash
psort.py -o l2tcsv -w ./timeline/full_timeline.csv ./timeline/evidence.plaso

```

For collaborative analysis, import directly into Timesketch:

```bash
timesketch_importer \
  --host http://localhost:5000 \
  --username analyst \
  --password password \
  --sketch_id 1 \
  --timeline_name "Example Timeline" \
  ./timeline/evidence.plaso

```

## Source File Locations

Critical implementation files for Digital Forensics automation include:

- [`skills/performing-memory-forensics-with-volatility3/SKILL.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/skills/performing-memory-forensics-with-volatility3/SKILL.md) — Full specification for memory analysis workflows
- [`skills/performing-memory-forensics-with-volatility3/scripts/agent.py`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/skills/performing-memory-forensics-with-volatility3/scripts/agent.py) — Python wrapper for Volatility 3 plugins
- [`skills/performing-windows-artifact-analysis-with-eric-zimmerman-tools/SKILL.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/skills/performing-windows-artifact-analysis-with-eric-zimmerman-tools/SKILL.md) — Documentation for KAPE and EZ Tools integration
- [`skills/performing-windows-artifact-analysis-with-eric-zimmerman-tools/scripts/agent.py`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/skills/performing-windows-artifact-analysis-with-eric-zimmerman-tools/scripts/agent.py) — Automation for Windows artifact parsing pipelines
- [`skills/performing-timeline-reconstruction-with-plaso/SKILL.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/skills/performing-timeline-reconstruction-with-plaso/SKILL.md) — Plaso workflow and export specifications
- [`skills/performing-network-forensics-with-wireshark/SKILL.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/skills/performing-network-forensics-with-wireshark/SKILL.md) — Network packet capture methodology
- [`skills/analyzing-windows-shellbag-artifacts/SKILL.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/skills/analyzing-windows-shellbag-artifacts/SKILL.md) — Shellbag parsing technical guide
- [`skills/analyzing-mft-for-deleted-file-recovery/SKILL.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/skills/analyzing-mft-for-deleted-file-recovery/SKILL.md) — MFT carving and deleted file recovery procedures

## Summary

- The **Anthropic Cybersecurity Skills** repository organizes Digital Forensics capabilities as self-contained units under `skills/` with standardized `subdomain: digital-forensics` metadata.
- Each skill provides **executable Python agents** ([`scripts/agent.py`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/scripts/agent.py)) that automate industry-standard tools including Volatility 3, Plaso, KAPE, and Wireshark.
- The repository covers **memory forensics**, **disk imaging**, **timeline reconstruction**, **network analysis**, and **mobile device examination**.
- Skills follow a **uniform structure** with [`SKILL.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/SKILL.md) specifications, automation scripts, and reference documentation for immediate deployment in incident response workflows.

## Frequently Asked Questions

### How do I identify Digital Forensics skills within the repository?

Locate the [`SKILL.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/SKILL.md) file in each skill directory and verify that the YAML header contains `subdomain: digital-forensics`. This field categorizes the skill within the Digital Forensics domain regardless of the specific artifact type being analyzed.

### What forensic tools are automated by these skills?

The repository automates **Volatility 3** for memory analysis, **KAPE** and **Eric Zimmerman Tools** for Windows artifacts, **Plaso** for timeline creation, **Wireshark/tshark** for network forensics, **Autopsy** for disk imaging, and **Apktool** for mobile malware analysis. Each skill wraps these CLI tools in Python automation scripts.

### Can these skills be integrated into enterprise incident response pipelines?

Yes. Each skill's [`scripts/agent.py`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/scripts/agent.py) accepts command-line arguments and outputs structured JSON or CSV reports, enabling integration with SOAR platforms, CI/CD pipelines, and automated ticketing systems without requiring manual GUI interaction.

### How do I run a Digital Forensics skill without installing dependencies?

While the repository provides automation scripts, you must install the underlying forensic tools (Volatility 3, Plaso, etc.) separately as system dependencies. The [`SKILL.md`](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/blob/main/SKILL.md) file in each directory lists specific installation commands for Ubuntu, Windows, and macOS environments.