performing-disk-forensics-investigation
mukul975/Anthropic-Cybersecurity-Skills
A detailed guide for conducting professional disk forensics investigations, covering the entire lifecycle from evidence acquisition to artifact analysis. This includes establishing a strict chain of custody, performing bit-for-bit forensic imaging using write blockers, identifying file system structures (MFT, inodes), recovering deleted files, analyzing key artifacts (Prefetch, Amcache), and reconstructing precise timelines of activity for incident response cases.