forensics-disk-analysis-endpoint-analyze - Perform digital forensics on compromised endpoints
Performs digital forensics on endpoints with memory acquisition, disk imaging, artifact analysis, and timeline reconstruction.
Tags
Updated: 2026-05-09Typical Outputs
What this skill does
- acquire memory dump
- capture volatile data
- create disk image
- analyze memory processes
- scan network connections
- detect process injection
- extract files from memory
- analyze registry artifacts
- parse Windows artifacts
- reconstruct event timeline
- generate forensic report
Inputs
- target endpoint
- administrative credentials
- forensic workstation
- memory acquisition tool
- disk imaging tool
- write-blocker
Outputs
- memory dump file
- disk image file
- evidence logs
- analysis results
- event timeline
- forensic report
- indicators of compromise
Requirements
- forensic workstation with analysis tools
- write-blocker for disk imaging
- secure evidence storage
- administrative access to target endpoint
- Volatility 3 framework
