LogoClawIndex
CasesSkillsAbout
LogoClawIndex

forensics-disk-analysis-endpoint-analyze - Perform digital forensics on compromised endpoints

Performs digital forensics on endpoints with memory acquisition, disk imaging, artifact analysis, and timeline reconstruction.

Tags

Updated: 2026-05-09
endpointforensicsmemory-analysisdisk-imagingincident-investigation

Capabilities

acquire memory dumpcapture volatile datacreate disk imageanalyze memory processes

Typical Inputs

target endpointadministrative credentialsforensic workstation

Typical Outputs

memory dump filedisk image fileevidence logs

What this skill does

  • acquire memory dump
  • capture volatile data
  • create disk image
  • analyze memory processes
  • scan network connections
  • detect process injection
  • extract files from memory
  • analyze registry artifacts
  • parse Windows artifacts
  • reconstruct event timeline
  • generate forensic report

Inputs

  • target endpoint
  • administrative credentials
  • forensic workstation
  • memory acquisition tool
  • disk imaging tool
  • write-blocker

Outputs

  • memory dump file
  • disk image file
  • evidence logs
  • analysis results
  • event timeline
  • forensic report
  • indicators of compromise

Requirements

  • forensic workstation with analysis tools
  • write-blocker for disk imaging
  • secure evidence storage
  • administrative access to target endpoint
  • Volatility 3 framework

Source

  • Spec: SKILL.md

ClawIndex

OpenClaw Skills & Use Case Index

ClawIndex is an ecosystem-driven index of OpenClaw skills and real-world use cases.

Index

Skills·
Cases

Meta

About·
Disclaimer·
Email·
GitHub
© 2026 ClawIndex All Rights Reserved.