Conduct forensic investigation of suspected breaches including evidence collection and timeline reconstruction.
From incident-responsenpx claudepluginhub sethdford/claude-skills --plugin security-incident-responseaffected system or incident detailsChain these steps:
forensic-analysis-guide to develop forensic investigation planevidence-preservation to collect and preserve digital evidenceroot-cause-analysis-security to determine how breach occurredDeliverables:
After completion, suggest follow-up commands: respond-to-incident, write-postmortem.