feat: digital-forensics-expert skill package v0.1.0
This commit is contained in:
31
PROVENANCE.md
Normal file
31
PROVENANCE.md
Normal file
@@ -0,0 +1,31 @@
|
||||
# Data provenance — digital-forensics-expert
|
||||
|
||||
Where the content of this skill package comes from, counted by
|
||||
content items (tasks, competences, tools, evidence entries, curated
|
||||
knowledge). Rendered live by Gitea:
|
||||
|
||||
```mermaid
|
||||
%%{init: {'theme':'base','themeVariables':{'pie1':'#f9a825','pie2':'#1e88e5','pie3':'#ff355e','pie4':'#d97757','pie5':'#8e24aa','pieOuterStrokeWidth':'0px','pieSectionTextColor':'#fff'}}}%%
|
||||
pie showData
|
||||
title Content sources — digital-forensics-expert
|
||||
"ESCO (occupation & competences)" : 78
|
||||
"O*NET (tasks & tools)" : 105
|
||||
"Job boards (market evidence)" : 101
|
||||
"Anthropic official Claude skills" : 9
|
||||
"External AI skill packs (mapped)" : 116
|
||||
```
|
||||
|
||||
| Source | Items | Share | Files |
|
||||
|---|---|---|---|
|
||||
| ESCO (occupation & competences) | 78 | 19.1 % | references/profile.md, references/skills.md |
|
||||
| O*NET (tasks & tools) | 105 | 25.7 % | references/tasks.md, references/tools.md |
|
||||
| Job boards (market evidence) | 101 | 24.7 % | references/market.md (full report) + "Market evidence" headline sections |
|
||||
| Wikipedia & AI expert curation | 0 | 0.0 % | glossary, literature, usecases, intake, quality, evals/ |
|
||||
| Anthropic official Claude skills | 9 | 2.2 % | references/ai-skills.md, section "anthropics/skills" (official Claude Code skills) |
|
||||
| External AI skill packs (mapped) | 116 | 28.4 % | references/ai-skills.md (per-source attribution inside) |
|
||||
| Stack Exchange practitioner Q&A (CC-BY-SA) | 0 | 0.0 % | references/practitioner-qa.md (per-entry attribution inside) |
|
||||
|
||||
Licensing: O*NET (USDOL/ETA, CC BY 4.0) · ESCO (© European Union) ·
|
||||
job-ad evidence via official APIs (JSearch/Adzuna) · Wikipedia content
|
||||
paraphrased with source URLs — never copied · external AI skills are
|
||||
linked, not copied (Apache-2.0/MIT/source-available, see ai-skills.md).
|
||||
80
SKILL.md
Normal file
80
SKILL.md
Normal file
@@ -0,0 +1,80 @@
|
||||
---
|
||||
name: digital-forensics-expert
|
||||
description: "Occupational skill for the role 'digital forensics expert' (also: computer forensics consultant, computer forensics investigator, computer forensics expert, digital forensics analyst, digital forensics specialist, digital forensics experts). Use when the user asks for typical digital forensics expert work such as: Adhere to legal policies and procedures related to handling digital media.; Analyze log files or other digital information to identify the perpetrators of network intrusions.; Conduct predictive or reactive analyses on security measures to support cyber security initiatives."
|
||||
---
|
||||
|
||||
# Digital Forensics Expert
|
||||
|
||||
Digital forensics experts retrieve and analyse information from computers and other types of data storage devices. They examine digital media that may have been hidden, encrypted or damaged, in a forensic manner with the aim to identify, preserve, recover, analyse and present facts and opinions about the digital information.
|
||||
|
||||
## Core workflow
|
||||
|
||||
1. Adhere to legal policies and procedures related to handling digital media.
|
||||
2. Analyze log files or other digital information to identify the perpetrators of network intrusions.
|
||||
3. Conduct predictive or reactive analyses on security measures to support cyber security initiatives.
|
||||
4. Create system images or capture network settings from information technology environments to preserve as evidence.
|
||||
5. Develop plans for investigating alleged computer crimes, violations, or suspicious activity.
|
||||
6. Develop policies or requirements for data collection, processing, or reporting.
|
||||
7. Duplicate digital evidence to use for data recovery and analysis procedures.
|
||||
8. Identify or develop reverse-engineering tools to improve system capabilities or detect vulnerabilities.
|
||||
|
||||
## How to use this skill
|
||||
|
||||
- Read [references/profile.md](references/profile.md) for the occupation profile and scope.
|
||||
- Consult [references/tasks.md](references/tasks.md) for the full task and activity inventory.
|
||||
- Check [references/skills.md](references/skills.md) for essential vs. optional competences.
|
||||
- Check [references/tools.md](references/tools.md) for the software commonly used in this role.
|
||||
- See [references/ai-skills.md](references/ai-skills.md) — matched external AI agent skills (per-source attribution).
|
||||
|
||||
## Key competences (essential)
|
||||
|
||||
- apply reverse engineering
|
||||
- attack vectors
|
||||
- audit techniques
|
||||
- check methods
|
||||
- computer forensics
|
||||
- cyber attack counter-measures
|
||||
- cyber security
|
||||
- develop information security strategy
|
||||
- digital data processing
|
||||
- educate on data confidentiality
|
||||
- establish an ICT security prevention plan
|
||||
- forensic intelligence
|
||||
- gather data for forensic purposes
|
||||
- GDPR
|
||||
- ICT infrastructure
|
||||
|
||||
## Hot technologies
|
||||
|
||||
- Kubernetes
|
||||
- Slack
|
||||
- IBM Terraform
|
||||
- Amazon Web Services AWS software
|
||||
- Microsoft Access
|
||||
- ServiceNow
|
||||
- Structured query language SQL
|
||||
- C
|
||||
- Go
|
||||
- Microsoft Azure software
|
||||
|
||||
|
||||
<!-- hot-tech -->
|
||||
|
||||
## Hot technologies
|
||||
|
||||
Top tools from 30 gated job ads (see references/market.md, as of 2026-07-11):
|
||||
|
||||
- X-Ways — 33 %
|
||||
- EnCase — 30 %
|
||||
- Cellebrite — 23 %
|
||||
- FTK — 23 %
|
||||
- Magnet Axiom — 13 %
|
||||
- Axiom — 10 %
|
||||
- Forensic Explorer — 10 %
|
||||
- Nuix — 10 %
|
||||
- Oxygen Forensic® — 10 %
|
||||
|
||||
<!-- hot-tech -->
|
||||
|
||||
---
|
||||
*Sources: ESCO v1.2.1 (http://data.europa.eu/esco/occupation/0c448a27-10ec-43ba-b880-d9938bade424), O*NET 30.3 (15-1299.06). See manifest.json for licensing/attribution.*
|
||||
160
manifest.json
Normal file
160
manifest.json
Normal file
@@ -0,0 +1,160 @@
|
||||
{
|
||||
"name": "digital-forensics-expert",
|
||||
"title": "digital forensics expert",
|
||||
"version": "0.1.0",
|
||||
"layer": "core",
|
||||
"language": "en",
|
||||
"generated": "2026-07-07",
|
||||
"ids": {
|
||||
"esco_uri": "http://data.europa.eu/esco/occupation/0c448a27-10ec-43ba-b880-d9938bade424",
|
||||
"esco_code": "2529.2",
|
||||
"isco_group": "2529",
|
||||
"onet_soc": "15-1299.06",
|
||||
"crosswalk_match": "exactMatch"
|
||||
},
|
||||
"sources": [
|
||||
{
|
||||
"name": "ESCO",
|
||||
"version": "1.2.1",
|
||||
"url": "https://esco.ec.europa.eu/"
|
||||
},
|
||||
{
|
||||
"name": "O*NET",
|
||||
"version": "30.3",
|
||||
"url": "https://www.onetcenter.org/",
|
||||
"license": "CC BY 4.0"
|
||||
}
|
||||
],
|
||||
"attribution": "This package includes information from the O*NET Database (v30.3) by the U.S. Department of Labor, Employment and Training Administration (USDOL/ETA), CC BY 4.0. skillfactor is not endorsed by USDOL/ETA. ESCO data (v1.2.1) (c) European Union, used per the ESCO download conditions: https://esco.ec.europa.eu/en/use-esco/download",
|
||||
"counts": {
|
||||
"tasks": 20,
|
||||
"dwas": 20,
|
||||
"skills_essential": 40,
|
||||
"skills_optional": 37,
|
||||
"software": 64
|
||||
},
|
||||
"enrichment_ai_skills": {
|
||||
"generated": "2026-07-14",
|
||||
"method": "deterministic mapping (ISCO prefix + title/competence keywords)",
|
||||
"sources": {
|
||||
"anthropics/skills": {
|
||||
"repo": "https://github.com/anthropics/skills",
|
||||
"commit": "f6656c1",
|
||||
"license": "Apache-2.0; the document skills (docx/pdf/pptx/xlsx) are source-available \u2014 see the LICENSE.txt in the upstream skill folder",
|
||||
"skills": 6
|
||||
},
|
||||
"obra/superpowers": {
|
||||
"repo": "https://github.com/obra/superpowers",
|
||||
"commit": "d884ae0",
|
||||
"license": "MIT (c) Jesse Vincent",
|
||||
"skills": 12
|
||||
},
|
||||
"wshobson/agents": {
|
||||
"repo": "https://github.com/wshobson/agents",
|
||||
"commit": "6fd3247",
|
||||
"license": "MIT (c) Seth Hobson",
|
||||
"skills": 12
|
||||
},
|
||||
"NVIDIA/skills": {
|
||||
"repo": "https://github.com/NVIDIA/skills",
|
||||
"commit": "153b14b",
|
||||
"license": "CC-BY-4.0 (skills/docs), Apache-2.0 (code)",
|
||||
"skills": 12
|
||||
},
|
||||
"veniceai/skills": {
|
||||
"repo": "https://github.com/veniceai/skills",
|
||||
"commit": "de089fa",
|
||||
"license": "MIT",
|
||||
"skills": 5
|
||||
},
|
||||
"czlonkowski/n8n-skills": {
|
||||
"repo": "https://github.com/czlonkowski/n8n-skills",
|
||||
"commit": "9ea3aa5",
|
||||
"license": "MIT",
|
||||
"skills": 12
|
||||
},
|
||||
"mukul975/Anthropic-Cybersecurity-Skills": {
|
||||
"repo": "https://github.com/mukul975/Anthropic-Cybersecurity-Skills",
|
||||
"commit": "673da1f",
|
||||
"license": "Apache-2.0",
|
||||
"skills": 9
|
||||
},
|
||||
"a5c-ai/babysitter": {
|
||||
"repo": "https://github.com/a5c-ai/babysitter",
|
||||
"commit": "44a5d58b",
|
||||
"license": "MIT",
|
||||
"skills": 5
|
||||
},
|
||||
"brycewang-stanford/Auto-Empirical-Research-Skills": {
|
||||
"repo": "https://github.com/brycewang-stanford/Auto-Empirical-Research-Skills",
|
||||
"commit": "85bf545",
|
||||
"license": "CC-BY-4.0",
|
||||
"skills": 1
|
||||
},
|
||||
"mhattingpete/claude-skills-marketplace": {
|
||||
"repo": "https://github.com/mhattingpete/claude-skills-marketplace",
|
||||
"commit": "3fa16a9",
|
||||
"license": "Apache-2.0",
|
||||
"skills": 1
|
||||
},
|
||||
"alirezarezvani/claude-skills": {
|
||||
"repo": "https://github.com/alirezarezvani/claude-skills",
|
||||
"commit": "0241f43",
|
||||
"license": "MIT",
|
||||
"skills": 1
|
||||
},
|
||||
"ljagiello/ctf-skills": {
|
||||
"repo": "https://github.com/ljagiello/ctf-skills",
|
||||
"commit": "d19f35f",
|
||||
"license": "MIT",
|
||||
"skills": 1
|
||||
},
|
||||
"Sushegaad/Claude-Skills-Governance-Risk-and-Compliance": {
|
||||
"repo": "https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance",
|
||||
"commit": "71d8920",
|
||||
"license": "MIT",
|
||||
"skills": 1
|
||||
},
|
||||
"foryourhealth111-pixel/Vibe-Skills": {
|
||||
"repo": "https://github.com/foryourhealth111-pixel/Vibe-Skills",
|
||||
"commit": "34429a8",
|
||||
"license": "Apache-2.0",
|
||||
"skills": 1
|
||||
},
|
||||
"davila7/claude-code-templates": {
|
||||
"repo": "https://github.com/davila7/claude-code-templates",
|
||||
"commit": "fa79251",
|
||||
"license": "MIT",
|
||||
"skills": 1
|
||||
}
|
||||
},
|
||||
"total_skills": 80,
|
||||
"tiers": {
|
||||
"core": 33,
|
||||
"adjacent": 47
|
||||
}
|
||||
},
|
||||
"provenance": {
|
||||
"items": {
|
||||
"esco": 78,
|
||||
"onet": 105,
|
||||
"jobads": 101,
|
||||
"wiki_ai": 0,
|
||||
"anthropic": 9,
|
||||
"ai_skills": 116,
|
||||
"stackx": 0
|
||||
},
|
||||
"share_percent": {
|
||||
"esco": 19.1,
|
||||
"onet": 25.7,
|
||||
"jobads": 24.7,
|
||||
"wiki_ai": 0.0,
|
||||
"anthropic": 2.2,
|
||||
"ai_skills": 28.4,
|
||||
"stackx": 0.0
|
||||
},
|
||||
"method": "content items per source category"
|
||||
},
|
||||
"collar": "white",
|
||||
"computer_work": true
|
||||
}
|
||||
218
references/ai-skills.md
Normal file
218
references/ai-skills.md
Normal file
@@ -0,0 +1,218 @@
|
||||
# External AI agent skills — digital-forensics-expert
|
||||
|
||||
Proven, publicly available AI agent skills mapped to this occupation.
|
||||
Nothing is copied from the sources: every entry is a name, a one-line
|
||||
summary and a link to the upstream skill package. Each section names
|
||||
its source repository, commit, license and retrieval date.
|
||||
|
||||
**Tiers:** `core` = the skill directly exercises a top market hard
|
||||
skill, tool or method (from gated job-ad evidence) or an essential
|
||||
ESCO competence of this occupation; `adjacent` =
|
||||
plausibly useful, secondary. Entries are capped at 12 per source
|
||||
and 80 in total per occupation (core first,
|
||||
strongest matches survive); everything beyond the caps is excluded
|
||||
and logged in the pipeline audit trail, not in this package.
|
||||
|
||||
_Matched deterministically (ISCO group + title/competence keywords,
|
||||
tiered against market evidence + ESCO essentials) by
|
||||
`pipeline/p5_enrich_ai_skills.py` on 2026-07-14._
|
||||
|
||||
## Source: anthropics/skills
|
||||
|
||||
- Repository: [https://github.com/anthropics/skills](https://github.com/anthropics/skills) (commit `f6656c1`, retrieved 2026-07-14)
|
||||
- License: Apache-2.0; the document skills (docx/pdf/pptx/xlsx) are source-available — see the LICENSE.txt in the upstream skill folder
|
||||
|
||||
| Skill | Tier | What it adds | Upstream |
|
||||
|---|---|---|---|
|
||||
| `webapp-testing` | adjacent | Toolkit for interacting with and testing local web applications using Playwright. Supports verifying frontend functionality, debugging UI behavior, capturing browser screenshots, and viewing browser logs. | [source](https://github.com/anthropics/skills/tree/main/skills/webapp-testing) |
|
||||
| `mcp-builder` | adjacent | Guide for creating high-quality MCP (Model Context Protocol) servers that enable LLMs to interact with external services through well-designed tools. Use when building MCP servers to integrate external APIs or services, whether in Python … | [source](https://github.com/anthropics/skills/tree/main/skills/mcp-builder) |
|
||||
| `claude-api` | adjacent | Reference for the Claude API / Anthropic SDK — model ids, pricing, params, streaming, tool use, MCP, agents, caching, token counting, model migration. TRIGGER — read BEFORE opening the target file; don't skip because it "looks like a … | [source](https://github.com/anthropics/skills/tree/main/skills/claude-api) |
|
||||
| `skill-creator` | adjacent | Create new skills, modify and improve existing skills, and measure skill performance. Use when users want to create a skill from scratch, edit, or optimize an existing skill, run evals to test a skill, benchmark skill performance with … | [source](https://github.com/anthropics/skills/tree/main/skills/skill-creator) |
|
||||
| `docx` | adjacent | Use this skill whenever the user wants to create, read, edit, or manipulate Word documents (.docx files) or Word templates (.dotx files). Triggers include: any mention of 'Word doc', 'word document', '.docx', '.dotx', or requests to … | [source](https://github.com/anthropics/skills/tree/main/skills/docx) |
|
||||
| `pdf` | adjacent | Use this skill whenever the user wants to do anything with PDF files. This includes reading or extracting text/tables from PDFs, combining or merging multiple PDFs into one, splitting PDFs apart, rotating pages, adding watermarks, creating … | [source](https://github.com/anthropics/skills/tree/main/skills/pdf) |
|
||||
|
||||
## Source: obra/superpowers
|
||||
|
||||
- Repository: [https://github.com/obra/superpowers](https://github.com/obra/superpowers) (commit `d884ae0`, retrieved 2026-07-14)
|
||||
- License: MIT (c) Jesse Vincent
|
||||
|
||||
| Skill | Tier | What it adds | Upstream |
|
||||
|---|---|---|---|
|
||||
| `verification-before-completion` | adjacent | Use when about to claim work is complete, fixed, or passing, before committing or creating PRs - requires running verification commands and confirming output before making any success claims; evidence before assertions always | [source](https://github.com/obra/superpowers/tree/main/skills/verification-before-completion) |
|
||||
| `test-driven-development` | adjacent | Use when implementing any feature or bugfix, before writing implementation code | [source](https://github.com/obra/superpowers/tree/main/skills/test-driven-development) |
|
||||
| `using-git-worktrees` | adjacent | Use when starting feature work that needs isolation from current workspace or before executing implementation plans - ensures an isolated workspace exists via native tools or git worktree fallback | [source](https://github.com/obra/superpowers/tree/main/skills/using-git-worktrees) |
|
||||
| `executing-plans` | adjacent | Use when you have a written implementation plan to execute in a separate session with review checkpoints | [source](https://github.com/obra/superpowers/tree/main/skills/executing-plans) |
|
||||
| `systematic-debugging` | adjacent | Use when encountering any bug, test failure, or unexpected behavior, before proposing fixes | [source](https://github.com/obra/superpowers/tree/main/skills/systematic-debugging) |
|
||||
| `writing-plans` | adjacent | Use when you have a spec or requirements for a multi-step task, before touching code | [source](https://github.com/obra/superpowers/tree/main/skills/writing-plans) |
|
||||
| `writing-skills` | adjacent | Use when creating new skills, editing existing skills, or verifying skills work before deployment | [source](https://github.com/obra/superpowers/tree/main/skills/writing-skills) |
|
||||
| `brainstorming` | adjacent | You MUST use this before any creative work - creating features, building components, adding functionality, or modifying behavior. Explores user intent, requirements and design before implementation. | [source](https://github.com/obra/superpowers/tree/main/skills/brainstorming) |
|
||||
| `dispatching-parallel-agents` | adjacent | Use when facing 2+ independent tasks that can be worked on without shared state or sequential dependencies | [source](https://github.com/obra/superpowers/tree/main/skills/dispatching-parallel-agents) |
|
||||
| `finishing-a-development-branch` | adjacent | Use when implementation is complete, all tests pass, and you need to decide how to integrate the work - guides completion of development work by presenting structured options for merge, PR, or cleanup | [source](https://github.com/obra/superpowers/tree/main/skills/finishing-a-development-branch) |
|
||||
| `receiving-code-review` | adjacent | Use when receiving code review feedback, before implementing suggestions, especially if feedback seems unclear or technically questionable - requires technical rigor and verification, not performative agreement or blind implementation | [source](https://github.com/obra/superpowers/tree/main/skills/receiving-code-review) |
|
||||
| `requesting-code-review` | adjacent | Use when completing tasks, implementing major features, or before merging to verify work meets requirements | [source](https://github.com/obra/superpowers/tree/main/skills/requesting-code-review) |
|
||||
|
||||
## Source: wshobson/agents
|
||||
|
||||
- Repository: [https://github.com/wshobson/agents](https://github.com/wshobson/agents) (commit `6fd3247`, retrieved 2026-07-14)
|
||||
- License: MIT (c) Seth Hobson
|
||||
|
||||
| Skill | Tier | What it adds | Upstream |
|
||||
|---|---|---|---|
|
||||
| `memory-forensics` | core | Master memory forensics techniques including memory acquisition, process analysis, and artifact extraction using Volatility and related tools. Use when analyzing memory dumps, investigating incidents, or performing malware analysis from … | [source](https://github.com/wshobson/agents/tree/main/plugins/reverse-engineering/skills/memory-forensics) |
|
||||
| `stride-analysis-patterns` | core | Apply STRIDE methodology to systematically identify threats. Use when analyzing system security, conducting threat modeling sessions, or creating security documentation. | [source](https://github.com/wshobson/agents/tree/main/plugins/security-scanning/skills/stride-analysis-patterns) |
|
||||
| `sast-configuration` | core | Configure Static Application Security Testing (SAST) tools for automated vulnerability detection in application code. Use when setting up security scanning, implementing DevSecOps practices, or automating code vulnerability detection. | [source](https://github.com/wshobson/agents/tree/main/plugins/security-scanning/skills/sast-configuration) |
|
||||
| `attack-tree-construction` | core | Build comprehensive attack trees to visualize threat paths. Use when mapping attack scenarios, identifying defense gaps, or communicating security risks to stakeholders. | [source](https://github.com/wshobson/agents/tree/main/plugins/security-scanning/skills/attack-tree-construction) |
|
||||
| `comprehensive-review-security-auditor (agent)` | core | Expert security auditor specializing in DevSecOps, comprehensive cybersecurity, and compliance frameworks. Masters vulnerability assessment, threat modeling, secure authentication (OAuth2/OIDC), OWASP standards, cloud security, and … | [source](https://github.com/wshobson/agents/tree/main/plugins/comprehensive-review/agents/security-auditor.md) |
|
||||
| `security-compliance-security-auditor (agent)` | core | Expert security auditor specializing in DevSecOps, comprehensive cybersecurity, and compliance frameworks. Masters vulnerability assessment, threat modeling, secure authentication (OAuth2/OIDC), OWASP standards, cloud security, and … | [source](https://github.com/wshobson/agents/tree/main/plugins/security-compliance/agents/security-auditor.md) |
|
||||
| `frontend-security-coder (agent)` | core | Expert in secure frontend coding practices specializing in XSS prevention, output sanitization, and client-side security patterns. Use PROACTIVELY for frontend security implementations or client-side security code reviews. | [source](https://github.com/wshobson/agents/tree/main/plugins/frontend-mobile-security/agents/frontend-security-coder.md) |
|
||||
| `security-requirement-extraction` | core | Derive security requirements from threat models and business context. Use when translating threats into actionable requirements, creating security user stories, or building security test cases. | [source](https://github.com/wshobson/agents/tree/main/plugins/security-scanning/skills/security-requirement-extraction) |
|
||||
| `threat-mitigation-mapping` | core | Map identified threats to appropriate security controls and mitigations. Use when prioritizing security investments, creating remediation plans, or validating control effectiveness. | [source](https://github.com/wshobson/agents/tree/main/plugins/security-scanning/skills/threat-mitigation-mapping) |
|
||||
| `protocol-reverse-engineering` | core | Master network protocol reverse engineering including packet analysis, protocol dissection, and custom protocol documentation. Use when analyzing network traffic, understanding proprietary protocols, or debugging network communication. | [source](https://github.com/wshobson/agents/tree/main/plugins/reverse-engineering/skills/protocol-reverse-engineering) |
|
||||
| `anti-reversing-techniques` | core | Understand anti-reversing, obfuscation, and protection techniques encountered during software analysis. Use this skill when analyzing malware evasion techniques, when implementing anti-debugging protections for CTF challenges, when reverse … | [source](https://github.com/wshobson/agents/tree/main/plugins/reverse-engineering/skills/anti-reversing-techniques) |
|
||||
| `postmortem-writing` | core | Write effective blameless postmortems with root cause analysis, timelines, and action items. Use when conducting incident reviews, writing postmortem documents, or improving incident response processes. | [source](https://github.com/wshobson/agents/tree/main/plugins/incident-response/skills/postmortem-writing) |
|
||||
|
||||
## Source: a5c-ai/babysitter
|
||||
|
||||
- Repository: [https://github.com/a5c-ai/babysitter](https://github.com/a5c-ai/babysitter) (commit `44a5d58b`, retrieved 2026-07-14)
|
||||
- License: MIT
|
||||
|
||||
| Skill | Tier | What it adds | Upstream |
|
||||
|---|---|---|---|
|
||||
| `chain-forensics` | core | On-chain analysis and transaction forensics for blockchain security investigations. Provides capabilities for tracing fund flows, identifying suspicious patterns, MEV analysis, and generating forensic reports for incident response. | [source](https://github.com/a5c-ai/babysitter/tree/44a5d58b/library/specializations/cryptography-blockchain/skills/chain-forensics) |
|
||||
| `incident-forensics` | core | Digital forensics and incident response capabilities. Analyze memory dumps with Volatility, parse filesystem artifacts, extract browser forensics, analyze Windows event logs, create forensic timelines, recover deleted files, and generate … | [source](https://github.com/a5c-ai/babysitter/tree/44a5d58b/library/specializations/security-research/skills/incident-forensics) |
|
||||
| `security-sandbox` | core | Isolated analysis environment management for malware and exploit testing. Create and manage isolated VMs, configure Cuckoo Sandbox, set up REMnux/FlareVM environments, manage Docker-based analysis containers, and capture filesystem and … | [source](https://github.com/a5c-ai/babysitter/tree/44a5d58b/library/specializations/security-research/skills/security-sandbox) |
|
||||
| `evm-analysis` | core | Deep EVM bytecode analysis and decompilation capabilities for smart contract security, gas optimization, and reverse engineering. Provides tools for analyzing opcodes, storage layouts, proxy patterns, and bytecode verification. | [source](https://github.com/a5c-ai/babysitter/tree/44a5d58b/library/specializations/cryptography-blockchain/skills/evm-analysis) |
|
||||
| `sast-analyzer` | core | Static Application Security Testing orchestration and analysis. Execute Semgrep, Bandit, ESLint security plugins, CodeQL, and other SAST tools. Parse, prioritize, and deduplicate findings across multiple tools with remediation guidance. | [source](https://github.com/a5c-ai/babysitter/tree/44a5d58b/library/specializations/security-compliance/skills/sast-analyzer) |
|
||||
|
||||
## Source: alirezarezvani/claude-skills
|
||||
|
||||
- Repository: [https://github.com/alirezarezvani/claude-skills](https://github.com/alirezarezvani/claude-skills) (commit `0241f43`, retrieved 2026-07-14)
|
||||
- License: MIT
|
||||
|
||||
| Skill | Tier | What it adds | Upstream |
|
||||
|---|---|---|---|
|
||||
| `security-pen-testing` | core | Use when the user asks to perform security audits, penetration testing, vulnerability scanning, OWASP Top 10 checks, or offensive security assessments. Covers static analysis, dependency scanning, secret detection, API security testing, … | [source](https://github.com/alirezarezvani/claude-skills/tree/0241f43/engineering-team/skills/security-pen-testing) |
|
||||
|
||||
## Source: brycewang-stanford/Auto-Empirical-Research-Skills
|
||||
|
||||
- Repository: [https://github.com/brycewang-stanford/Auto-Empirical-Research-Skills](https://github.com/brycewang-stanford/Auto-Empirical-Research-Skills) (commit `85bf545`, retrieved 2026-07-14)
|
||||
- License: CC-BY-4.0
|
||||
|
||||
| Skill | Tier | What it adds | Upstream |
|
||||
|---|---|---|---|
|
||||
| `cs-skills` | core | 10 computer science skills. Trigger: algorithms, systems research, software engineering, security papers. Design: theory, complexity analysis, code-centric research, and security methods. | [source](https://github.com/brycewang-stanford/Auto-Empirical-Research-Skills/tree/85bf545/skills/43-wentorai-research-plugins/skills/domains/cs) |
|
||||
|
||||
## Source: davila7/claude-code-templates
|
||||
|
||||
- Repository: [https://github.com/davila7/claude-code-templates](https://github.com/davila7/claude-code-templates) (commit `fa79251`, retrieved 2026-07-14)
|
||||
- License: MIT
|
||||
|
||||
| Skill | Tier | What it adds | Upstream |
|
||||
|---|---|---|---|
|
||||
| `senior-security` | core | Comprehensive security engineering skill for application security, penetration testing, security architecture, and compliance auditing. Includes security assessment tools, threat modeling, crypto implementation, and security automation. … | [source](https://github.com/davila7/claude-code-templates/tree/fa79251/cli-tool/components/skills/development/senior-security) |
|
||||
|
||||
## Source: foryourhealth111-pixel/Vibe-Skills
|
||||
|
||||
- Repository: [https://github.com/foryourhealth111-pixel/Vibe-Skills](https://github.com/foryourhealth111-pixel/Vibe-Skills) (commit `34429a8`, retrieved 2026-07-14)
|
||||
- License: Apache-2.0
|
||||
|
||||
| Skill | Tier | What it adds | Upstream |
|
||||
|---|---|---|---|
|
||||
| `receiving-code-review` | core | Review-feedback handling route for CodeRabbit, GitHub, PR, or human reviewer comments. Use before implementing suggestions to verify each finding. Do not use for a fresh code review, security audit, TDD, or final completion evidence. | [source](https://github.com/foryourhealth111-pixel/Vibe-Skills/tree/34429a8/bundled/skills/receiving-code-review) |
|
||||
|
||||
## Source: ljagiello/ctf-skills
|
||||
|
||||
- Repository: [https://github.com/ljagiello/ctf-skills](https://github.com/ljagiello/ctf-skills) (commit `d19f35f`, retrieved 2026-07-14)
|
||||
- License: MIT
|
||||
|
||||
| Skill | Tier | What it adds | Upstream |
|
||||
|---|---|---|---|
|
||||
| `ctf-forensics` | core | Provides digital forensics and signal analysis techniques for CTF challenges. Use when analyzing disk images, memory dumps, event logs, network captures, cryptocurrency transactions, steganography, PDF analysis, Windows registry, … | [source](https://github.com/ljagiello/ctf-skills/tree/d19f35f/ctf-forensics) |
|
||||
|
||||
## Source: mhattingpete/claude-skills-marketplace
|
||||
|
||||
- Repository: [https://github.com/mhattingpete/claude-skills-marketplace](https://github.com/mhattingpete/claude-skills-marketplace) (commit `3fa16a9`, retrieved 2026-07-14)
|
||||
- License: Apache-2.0
|
||||
|
||||
| Skill | Tier | What it adds | Upstream |
|
||||
|---|---|---|---|
|
||||
| `code-auditor` | core | Performs comprehensive codebase analysis covering architecture, code quality, security, performance, testing, and maintainability. Use when user wants to audit code quality, identify technical debt, find security issues, assess test … | [source](https://github.com/mhattingpete/claude-skills-marketplace/tree/3fa16a9/productivity-skills-plugin/skills/code-auditor) |
|
||||
|
||||
## Source: mukul975/Anthropic-Cybersecurity-Skills
|
||||
|
||||
- Repository: [https://github.com/mukul975/Anthropic-Cybersecurity-Skills](https://github.com/mukul975/Anthropic-Cybersecurity-Skills) (commit `673da1f`, retrieved 2026-07-14)
|
||||
- License: Apache-2.0
|
||||
|
||||
| Skill | Tier | What it adds | Upstream |
|
||||
|---|---|---|---|
|
||||
| `performing-endpoint-forensics-investigation` | core | Performs digital forensics investigation on compromised endpoints including memory acquisition, disk imaging, artifact analysis, and timeline reconstruction. Use when investigating security incidents, collecting evidence for legal … | [source](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/673da1f/skills/performing-endpoint-forensics-investigation) |
|
||||
| `performing-sqlite-database-forensics` | core | Perform forensic analysis of SQLite databases to recover deleted records from freelists and WAL files, decode encoded timestamps, and extract evidence from browser history, messaging apps, and mobile device databases. | [source](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/673da1f/skills/performing-sqlite-database-forensics) |
|
||||
| `implementing-cloud-trail-log-analysis` | core | Implementing AWS CloudTrail log analysis for security monitoring, threat detection, and forensic investigation using Athena, CloudWatch Logs Insights, and SIEM integration to identify unauthorized access, privilege escalation, and … | [source](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/673da1f/skills/implementing-cloud-trail-log-analysis) |
|
||||
| `conducting-memory-forensics-with-volatility` | core | Performs memory forensics analysis using Volatility 3 to extract evidence of malware execution, process injection, network connections, and credential theft from RAM dumps captured during incident response. Covers memory acquisition, … | [source](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/673da1f/skills/conducting-memory-forensics-with-volatility) |
|
||||
| `performing-insider-threat-investigation` | core | Investigates insider threat incidents involving employees, contractors, or trusted partners who misuse authorized access to steal data, sabotage systems, or violate security policies. Combines digital forensics, user behavior analytics, … | [source](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/673da1f/skills/performing-insider-threat-investigation) |
|
||||
| `recovering-from-ransomware-attack` | core | Executes structured recovery from a ransomware incident following NIST and CISA frameworks, including environment isolation, forensic evidence preservation, clean infrastructure rebuild, prioritized system restoration from verified … | [source](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/673da1f/skills/recovering-from-ransomware-attack) |
|
||||
| `performing-cloud-forensics-with-aws-cloudtrail` | core | Perform forensic investigation of AWS environments using CloudTrail logs to reconstruct attacker activity, identify compromised credentials, and analyze API call patterns. | [source](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/673da1f/skills/performing-cloud-forensics-with-aws-cloudtrail) |
|
||||
| `performing-cloud-storage-forensic-acquisition` | core | Perform forensic acquisition and analysis of cloud storage services including Google Drive, OneDrive, Dropbox, and Box by collecting both API-based remote data and local sync client artifacts from endpoint devices. | [source](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/673da1f/skills/performing-cloud-storage-forensic-acquisition) |
|
||||
| `performing-kubernetes-penetration-testing` | core | Kubernetes penetration testing systematically evaluates cluster security by simulating attacker techniques against the API server, kubelet, etcd, pods, RBAC, network policies, and secrets. Using tools | [source](https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/673da1f/skills/performing-kubernetes-penetration-testing) |
|
||||
|
||||
## Source: Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
|
||||
|
||||
- Repository: [https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance](https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance) (commit `71d8920`, retrieved 2026-07-14)
|
||||
- License: MIT
|
||||
|
||||
| Skill | Tier | What it adds | Upstream |
|
||||
|---|---|---|---|
|
||||
| `nzism` | core | Expert New Zealand Information Security Manual (NZISM) advisor for NZ government agencies and their supply chains. Use for NZISM control guidance, gap analysis, agency security obligations, classification framework (Unclassified through … | [source](https://github.com/Sushegaad/Claude-Skills-Governance-Risk-and-Compliance/tree/71d8920/plugins/nzism/skills/nzism) |
|
||||
|
||||
## Source: czlonkowski/n8n-skills
|
||||
|
||||
- Repository: [https://github.com/czlonkowski/n8n-skills](https://github.com/czlonkowski/n8n-skills) (commit `9ea3aa5`, retrieved 2026-07-14)
|
||||
- License: MIT
|
||||
|
||||
| Skill | Tier | What it adds | Upstream |
|
||||
|---|---|---|---|
|
||||
| `n8n-mcp-tools-expert` | adjacent | Expert guide for using n8n-mcp MCP tools effectively. Use when searching for nodes, validating configurations, accessing templates, managing workflows, managing credentials, auditing instance security, or using any n8n-mcp tool. Provides … | [source](https://github.com/czlonkowski/n8n-skills/tree/9ea3aa5/skills/n8n-mcp-tools-expert) |
|
||||
| `n8n-agents` | adjacent | Design n8n AI agents the right way. Use when building or editing any @n8n/n8n-nodes-langchain.* AI node — an AI Agent, LLM chain, Text Classifier, or Information Extractor — and whenever the user mentions AI agents, LLM with tools, tool … | [source](https://github.com/czlonkowski/n8n-skills/tree/9ea3aa5/skills/n8n-agents) |
|
||||
| `using-n8n-mcp-skills` | adjacent | Use when building, editing, validating, testing, or debugging an n8n workflow through the n8n-mcp MCP server — designing a flow, configuring a node, writing an expression or Code node, wiring credentials, or fixing one that misbehaves. The … | [source](https://github.com/czlonkowski/n8n-skills/tree/9ea3aa5/skills/using-n8n-mcp-skills) |
|
||||
| `n8n-code-tool` | adjacent | Write JavaScript or Python for the n8n Custom Code Tool (@n8n/n8n-nodes-langchain.toolCode) — the AI-agent-callable tool, NOT the workflow Code node. Use when building a Code Tool attached to an AI Agent, writing code that an LLM will … | [source](https://github.com/czlonkowski/n8n-skills/tree/9ea3aa5/skills/n8n-code-tool) |
|
||||
| `n8n-self-hosting` | adjacent | Deploy a production self-hosted n8n end-to-end to a fresh Linux VM over SSH, using Docker Compose behind a Caddy reverse proxy with automatic HTTPS. Use whenever the user wants to self-host, install, set up, provision, or deploy n8n on … | [source](https://github.com/czlonkowski/n8n-skills/tree/9ea3aa5/skills/n8n-self-hosting) |
|
||||
| `n8n-binary-and-data` | adjacent | Handle files and binary data in n8n correctly. Use when working with files, images, PDFs, attachments, uploads or downloads, base64, vision/multimodal input, or when an AI agent needs a file as tool input or output — and whenever the user … | [source](https://github.com/czlonkowski/n8n-skills/tree/9ea3aa5/skills/n8n-binary-and-data) |
|
||||
| `n8n-code-javascript` | adjacent | Write JavaScript code in n8n Code nodes. Use when writing JavaScript in n8n, using $input/$json/$node syntax, making HTTP requests with this.helpers / the $helpers global, working with dates using DateTime, troubleshooting Code node … | [source](https://github.com/czlonkowski/n8n-skills/tree/9ea3aa5/skills/n8n-code-javascript) |
|
||||
| `n8n-code-python` | adjacent | Write Python code in n8n Code nodes. Use when writing Python in n8n, using _input/_json/_node syntax, working with standard library, or need to understand Python limitations in n8n Code nodes. Use this skill when the user specifically … | [source](https://github.com/czlonkowski/n8n-skills/tree/9ea3aa5/skills/n8n-code-python) |
|
||||
| `n8n-error-handling` | adjacent | Wire n8n error handling so failures are loud, structured, and recoverable. Use when building any webhook/API workflow, a scheduled or unattended workflow, or any path where a silent failure would drop user-visible work — and whenever the … | [source](https://github.com/czlonkowski/n8n-skills/tree/9ea3aa5/skills/n8n-error-handling) |
|
||||
| `n8n-expression-syntax` | adjacent | Validate n8n expression syntax and fix common errors. Use when writing n8n expressions, using {{}} syntax, accessing $json/$node variables, troubleshooting expression errors, mapping data between nodes, or referencing webhook data in … | [source](https://github.com/czlonkowski/n8n-skills/tree/9ea3aa5/skills/n8n-expression-syntax) |
|
||||
| `n8n-multi-instance` | adjacent | Use when an n8n-mcp account targets more than one n8n instance — i.e. the `n8n_instances` tool is available, the user mentions multiple n8n instances or environments (prod vs staging, several teams or clients), a workflow / datatable / … | [source](https://github.com/czlonkowski/n8n-skills/tree/9ea3aa5/skills/n8n-multi-instance) |
|
||||
| `n8n-node-configuration` | adjacent | Operation-aware node configuration guidance. Use when configuring nodes, understanding property dependencies, determining required fields, choosing between get_node detail levels, or learning common configuration patterns by node type. … | [source](https://github.com/czlonkowski/n8n-skills/tree/9ea3aa5/skills/n8n-node-configuration) |
|
||||
|
||||
## Source: NVIDIA/skills
|
||||
|
||||
- Repository: [https://github.com/NVIDIA/skills](https://github.com/NVIDIA/skills) (commit `153b14b`, retrieved 2026-07-14)
|
||||
- License: CC-BY-4.0 (skills/docs), Apache-2.0 (code)
|
||||
|
||||
| Skill | Tier | What it adds | Upstream |
|
||||
|---|---|---|---|
|
||||
| `hsb-app` | adjacent | Discover and run Holoscan Sensor Bridge example applications on a connected devkit. Filters available apps by the user's platform, HSB software version, board type, and sensors. Supports timed execution, failure analysis, code-edit … | [source](https://github.com/NVIDIA/skills/tree/153b14b/skills/hsb-app) |
|
||||
| `digital-health-clinical-asr-setup` | adjacent | Stage 1 of Clinical ASR Flywheel. Use when bootstrapping a cycle: NVCF+MW disclosure, NVIDIA_API_KEY check, deps install, TTS+ASR smoke test. | [source](https://github.com/NVIDIA/skills/tree/153b14b/skills/digital-health-clinical-asr-setup) |
|
||||
| `digital-health-clinical-asr-eval` | adjacent | Stage 3 of Clinical ASR Flywheel. Score a NeMo manifest, produce the five-section KER leaderboard (by-ipa_source diagnostic). Not for ASR auth (/riva-asr). | [source](https://github.com/NVIDIA/skills/tree/153b14b/skills/digital-health-clinical-asr-eval) |
|
||||
| `digital-health-clinical-asr-build` | adjacent | Stage 2 of the Clinical ASR Flywheel. Use when curating clinical terms, tagging IPA, and synthesizing a NeMo manifest. NOT for scoring (use /digital-health-clinical-asr-eval). | [source](https://github.com/NVIDIA/skills/tree/153b14b/skills/digital-health-clinical-asr-build) |
|
||||
| `digital-health-clinical-asr-finetune` | adjacent | Stage 4 of the Clinical ASR Flywheel. Use when priority KER is above 0.3 to run stock NeMo SFT on Parakeet TDT v2 and offline cycle N+1 re-eval. NOT for generic word boosting (use /finetune-asr). | [source](https://github.com/NVIDIA/skills/tree/153b14b/skills/digital-health-clinical-asr-finetune) |
|
||||
| `deepstream-dev` | adjacent | NVIDIA DeepStream SDK 9.0 development with Python pyservicemaker API. Use when building video analytics pipelines, GStreamer-based video processing, TensorRT inference integration, object detection/tracking, or Kafka/message broker … | [source](https://github.com/NVIDIA/skills/tree/153b14b/skills/deepstream-dev) |
|
||||
| `nemo-mbridge-perf-moe-optimization-workflow` | adjacent | Systematic workflow for MoE training optimization in Megatron Bridge, based on the Megatron-Core MoE paper. Covers the Three Walls framework, parallel folding, recompute strategy, dispatcher choice, and CUDA-graph bring-up. | [source](https://github.com/NVIDIA/skills/tree/153b14b/skills/nemo-mbridge-perf-moe-optimization-workflow) |
|
||||
| `deepstream-sop` | adjacent | Use this skill when building, deploying, evaluating, debugging, or measuring latency for the DeepStream SOP Inference Microservice — a GPU-accelerated FastAPI service that detects whether operators perform assembly-line steps in order via … | [source](https://github.com/NVIDIA/skills/tree/153b14b/skills/deepstream-sop) |
|
||||
| `mcore-linting-and-formatting` | adjacent | Linting and formatting for Megatron-LM. Covers running autoformat.sh, tools (ruff, black, isort, pylint, mypy), and code style rules. | [source](https://github.com/NVIDIA/skills/tree/153b14b/skills/mcore-linting-and-formatting) |
|
||||
| `nemo-rl-docs` | adjacent | Documentation conventions for NeMo-RL. Covers docs/index.md updates and docstring format. Do NOT use for: bug fixes, test fixes, dependency bumps, refactoring, CI/CD changes, performance tuning, or any task that does not involve writing or … | [source](https://github.com/NVIDIA/skills/tree/153b14b/skills/nemo-rl-docs) |
|
||||
| `nemo-rl-session-memory` | adjacent | Manage durable working-session memory for coding agents. Use when a user asks to preserve or recover agent context across disconnects, VS Code restarts, long-running work, handoffs, or any session where important state should be written … | [source](https://github.com/NVIDIA/skills/tree/153b14b/skills/nemo-rl-session-memory) |
|
||||
| `rag-blueprint` | adjacent | NVIDIA RAG Blueprint — deploy, configure, troubleshoot, and manage. Handles any RAG action: deploy, install, start, enable, disable, toggle, change, configure, troubleshoot, debug, fix, shutdown, stop, or tear down any RAG feature or … | [source](https://github.com/NVIDIA/skills/tree/153b14b/skills/rag-blueprint) |
|
||||
|
||||
## Source: veniceai/skills
|
||||
|
||||
- Repository: [https://github.com/veniceai/skills](https://github.com/veniceai/skills) (commit `de089fa`, retrieved 2026-07-14)
|
||||
- License: MIT
|
||||
|
||||
| Skill | Tier | What it adds | Upstream |
|
||||
|---|---|---|---|
|
||||
| `venice-api-keys` | adjacent | Manage Venice API keys. Covers GET/POST/PATCH/DELETE /api_keys, GET /api_keys/{id}, GET /api_keys/rate_limits, GET /api_keys/rate_limits/log, the two-step /api_keys/generate_web3_key wallet flow, INFERENCE vs ADMIN key types, and per-key … | [source](https://github.com/veniceai/skills/tree/de089fa/skills/venice-api-keys) |
|
||||
| `venice-api-overview` | adjacent | High-level map of the Venice.ai API - base URL, authentication modes, endpoint categories, response headers, pricing model, error shape, and versioning. Load this first when starting any Venice integration. | [source](https://github.com/veniceai/skills/tree/de089fa/skills/venice-api-overview) |
|
||||
| `venice-auth` | adjacent | Authenticate to the Venice API with a Bearer API key or with an x402 / SIWE wallet. Covers header formats, the SIWE message fields, TTL and nonce rules, the venice-x402-client SDK, and how to choose between the two modes. | [source](https://github.com/veniceai/skills/tree/de089fa/skills/venice-auth) |
|
||||
| `venice-errors` | adjacent | Handle Venice API errors correctly. Covers the StandardError / DetailedError / ContentViolationError / X402InferencePaymentRequired body shapes, every meaningful status code (400, 401, 402, 403, 415, 422, 429, 500, 503, 504), the 402 … | [source](https://github.com/veniceai/skills/tree/de089fa/skills/venice-errors) |
|
||||
| `venice-responses` | adjacent | Use Venice's Alpha POST /responses endpoint - an OpenAI-compatible Responses API with typed output blocks (reasoning, message, function_call, web_search_call). Covers request shape, streaming, differences from /chat/completions, supported … | [source](https://github.com/veniceai/skills/tree/de089fa/skills/venice-responses) |
|
||||
147
references/market.md
Normal file
147
references/market.md
Normal file
@@ -0,0 +1,147 @@
|
||||
# Market evidence report — digital-forensics-expert
|
||||
|
||||
Source: **30 real job ads** (JSearch API, countries: us 30), extracted into the MSSQL evidence store; as of 2026-07-11.
|
||||
This report contains extracted, aggregated facts only — no ad text is
|
||||
reproduced (copyright / platform terms).
|
||||
|
||||
## Seniority distribution
|
||||
|
||||
| Seniority | Ads | Share |
|
||||
|---|---|---|
|
||||
| mid | 22 | 73 % |
|
||||
| senior | 7 | 23 % |
|
||||
| junior | 1 | 3 % |
|
||||
|
||||
## Tools — full market ranking
|
||||
|
||||
| # | Item | Ads | Share |
|
||||
|---|---|---|---|
|
||||
| 1 | X-Ways | 10 | 33 % |
|
||||
| 2 | EnCase | 9 | 30 % |
|
||||
| 3 | Cellebrite | 7 | 23 % |
|
||||
| 4 | FTK | 7 | 23 % |
|
||||
| 5 | Magnet Axiom | 4 | 13 % |
|
||||
| 6 | Axiom | 3 | 10 % |
|
||||
| 7 | Forensic Explorer | 3 | 10 % |
|
||||
| 8 | Nuix | 3 | 10 % |
|
||||
| 9 | Oxygen Forensic® | 3 | 10 % |
|
||||
|
||||
## Hard skills — full market ranking
|
||||
|
||||
| # | Item | Ads | Share |
|
||||
|---|---|---|---|
|
||||
| 1 | digital forensics | 25 | 83 % |
|
||||
| 2 | data recovery | 10 | 33 % |
|
||||
| 3 | incident response | 9 | 30 % |
|
||||
| 4 | forensic analysis | 7 | 23 % |
|
||||
| 5 | evidence preservation | 6 | 20 % |
|
||||
| 6 | malware analysis | 6 | 20 % |
|
||||
| 7 | forensic examination | 5 | 17 % |
|
||||
| 8 | report writing | 4 | 13 % |
|
||||
| 9 | steganography detection | 4 | 13 % |
|
||||
| 10 | artifact analysis | 3 | 10 % |
|
||||
| 11 | cyber security assessment | 3 | 10 % |
|
||||
| 12 | evidence acquisition | 3 | 10 % |
|
||||
| 13 | evidence analysis | 3 | 10 % |
|
||||
| 14 | network forensics | 3 | 10 % |
|
||||
| 15 | password cracking | 3 | 10 % |
|
||||
|
||||
## Methods — full market ranking
|
||||
|
||||
| # | Item | Ads | Share |
|
||||
|---|---|---|---|
|
||||
| 1 | chain of custody | 5 | 17 % |
|
||||
| 2 | host-based forensics | 3 | 10 % |
|
||||
| 3 | mobile device forensics | 3 | 10 % |
|
||||
|
||||
## Responsibilities — full market ranking
|
||||
|
||||
| # | Item | Ads | Share |
|
||||
|---|---|---|---|
|
||||
| 1 | emerging technology evaluation | 4 | 13 % |
|
||||
| 2 | evidence collection | 4 | 13 % |
|
||||
| 3 | forensic analysis | 4 | 13 % |
|
||||
| 4 | forensic examination | 4 | 13 % |
|
||||
| 5 | ci/ct investigation support | 3 | 10 % |
|
||||
| 6 | evidence analysis | 3 | 10 % |
|
||||
| 7 | expert witness testimony | 3 | 10 % |
|
||||
| 8 | report generation | 3 | 10 % |
|
||||
| 9 | report preparation | 3 | 10 % |
|
||||
| 10 | training event design | 3 | 10 % |
|
||||
|
||||
## Regional breakdown
|
||||
|
||||
> **Corpus note:** 30 relevant ads in total — below the 100-ad target for a fully reliable ranking. Percentages above should be read as indicative.
|
||||
|
||||
### US (us)
|
||||
|
||||
30 ads.
|
||||
|
||||
**Top hard skills:**
|
||||
|
||||
- digital forensics — 83 % (25 ads)
|
||||
- data recovery — 33 % (10 ads)
|
||||
- incident response — 30 % (9 ads)
|
||||
- forensic analysis — 23 % (7 ads)
|
||||
- evidence preservation — 20 % (6 ads)
|
||||
- malware analysis — 20 % (6 ads)
|
||||
- forensic examination — 17 % (5 ads)
|
||||
- report writing — 13 % (4 ads)
|
||||
- steganography detection — 13 % (4 ads)
|
||||
- artifact analysis — 10 % (3 ads)
|
||||
|
||||
**Top tools:**
|
||||
|
||||
- X-Ways — 33 % (10 ads)
|
||||
- EnCase — 30 % (9 ads)
|
||||
- Cellebrite — 23 % (7 ads)
|
||||
- FTK — 23 % (7 ads)
|
||||
- Magnet Axiom — 13 % (4 ads)
|
||||
- Axiom — 10 % (3 ads)
|
||||
- Forensic Explorer — 10 % (3 ads)
|
||||
- Nuix — 10 % (3 ads)
|
||||
- Oxygen Forensic® — 10 % (3 ads)
|
||||
- AWS — 7 % (2 ads)
|
||||
|
||||
**Seniority:** mid 73 % · senior 23 % · junior 3 %
|
||||
|
||||
### UK (gb)
|
||||
|
||||
**Insufficient evidence** — 0 ads (minimum for a regional ranking: 30). No ranking is reported for this region.
|
||||
|
||||
### EU/DACH (de, at, ch, nl)
|
||||
|
||||
**Insufficient evidence** — 0 ads (minimum for a regional ranking: 30). No ranking is reported for this region.
|
||||
|
||||
|
||||
## Job title variants in the market
|
||||
|
||||
| Title | Ads |
|
||||
|---|---|
|
||||
| Digital Forensics Examiner | 5 |
|
||||
| Digital Forensics Analyst | 2 |
|
||||
| Computer Forensics Specialist (Expert) - Digital Media Forensics with Security Clearance | 1 |
|
||||
| Computer Specialist - Network and Digital Forensics Examiner at Longeviti, LLC Washington DC | 1 |
|
||||
| Cyber Forensic Investigator – DFIR & ESI Expert | 1 |
|
||||
| Cyber Forensic Specialist | 1 |
|
||||
| Cyber Forensics Investigations Specialist | 1 |
|
||||
| Digital Forensic Analyst | 1 |
|
||||
| Digital Forensic Analyst (TS/SCI)- Senior & Mid | 1 |
|
||||
| Digital Forensics SME | 1 |
|
||||
| Digital Forensics Systems Specialist | 1 |
|
||||
| Digital Media Forensics Specialist - Expert | 1 |
|
||||
| Digital Media Forensics Specialist - Senior | 1 |
|
||||
| Expert Digital Media Forensics Team Support - USACIC with Security Clearance | 1 |
|
||||
| Expert Network Forensics Cybersecurity Analyst | 1 |
|
||||
| Forensic Analyst II | 1 |
|
||||
| Junior Digital Forensic Analyst | 1 |
|
||||
| Mid-Level Digital Forensic Analyst | 1 |
|
||||
| Remote Cyber Forensics & Exploitation Expert | 1 |
|
||||
| Senior Digital Forensic Analyst | 1 |
|
||||
| Senior Digital Forensic Analyst Site in Arlington | 1 |
|
||||
| Senior Digital Forensic Cyber Analyst; TS/SCI - Remote | 1 |
|
||||
| Senior Digital Forensics Analyst - Onsite in Arlington | 1 |
|
||||
| Senior Digital Forensics Analyst ( Python, Splunk, Arcsight) | 1 |
|
||||
| TS/SCI Digital Forensics Specialist | CI Poly | DFE | 1 |
|
||||
|
||||
Methodology: entities extracted per ad ({hard_skills, tools, methods, responsibilities, seniority}), normalized, counted as DISTINCT ads per entity; report threshold ≥ 3 ads. Headline sections in skills.md/tools.md use the stricter ≥ 20 % threshold.
|
||||
29
references/profile.md
Normal file
29
references/profile.md
Normal file
@@ -0,0 +1,29 @@
|
||||
# Occupation profile — digital forensics expert
|
||||
|
||||
- **ESCO URI:** http://data.europa.eu/esco/occupation/0c448a27-10ec-43ba-b880-d9938bade424
|
||||
- **ESCO code:** 2529.2
|
||||
- **ISCO-08 group:** 2529 — Database and network professionals not elsewhere classified
|
||||
- **O*NET-SOC:** 15-1299.06 — Digital Forensics Analysts (match: exactMatch)
|
||||
|
||||
## Description (ESCO)
|
||||
|
||||
Digital forensics experts retrieve and analyse information from computers and other types of data storage devices. They examine digital media that may have been hidden, encrypted or damaged, in a forensic manner with the aim to identify, preserve, recover, analyse and present facts and opinions about the digital information.
|
||||
|
||||
## Definition
|
||||
|
||||
nan
|
||||
|
||||
## Alternative labels
|
||||
|
||||
- computer forensics consultant
|
||||
- computer forensics investigator
|
||||
- computer forensics expert
|
||||
- digital forensics analyst
|
||||
- digital forensics specialist
|
||||
- digital forensics experts
|
||||
- ICT forensics expert
|
||||
- digital forensic expert
|
||||
- cyber forensics expert
|
||||
- cybersecurity analyst
|
||||
- information forensics expert
|
||||
- cybersecurity and forensic specialist
|
||||
103
references/skills.md
Normal file
103
references/skills.md
Normal file
@@ -0,0 +1,103 @@
|
||||
# Competences — digital forensics expert
|
||||
|
||||
Source: ESCO v1.2.1 occupation-skill relations (http://data.europa.eu/esco/occupation/0c448a27-10ec-43ba-b880-d9938bade424).
|
||||
|
||||
## Essential
|
||||
|
||||
- **apply reverse engineering** (skill/competence)
|
||||
- **attack vectors** (knowledge)
|
||||
- **audit techniques** (knowledge)
|
||||
- **check methods** (knowledge)
|
||||
- **computer forensics** (knowledge)
|
||||
- **cyber attack counter-measures** (knowledge)
|
||||
- **cyber security** (knowledge)
|
||||
- **develop information security strategy** (skill/competence)
|
||||
- **digital data processing** (nan)
|
||||
- **educate on data confidentiality** (skill/competence)
|
||||
- **establish an ICT security prevention plan** (skill/competence)
|
||||
- **forensic intelligence** (knowledge)
|
||||
- **gather data for forensic purposes** (skill/competence)
|
||||
- **GDPR** (knowledge)
|
||||
- **ICT infrastructure** (knowledge)
|
||||
- **ICT network security risks** (knowledge)
|
||||
- **ICT security legislation** (knowledge)
|
||||
- **ICT security standards** (knowledge)
|
||||
- **identify ICT security risks** (skill/competence)
|
||||
- **identify ICT system weaknesses** (skill/competence)
|
||||
- **implement ICT network diagnostic tools** (skill/competence)
|
||||
- **information confidentiality** (knowledge)
|
||||
- **levels of software testing** (knowledge)
|
||||
- **manage data for legal matters** (skill/competence)
|
||||
- **manage IT security compliances** (skill/competence)
|
||||
- **operating systems** (knowledge)
|
||||
- **penetration testing tool** (knowledge)
|
||||
- **perform forensic preservations of digital devices** (skill/competence)
|
||||
- **perform ICT security testing** (skill/competence)
|
||||
- **present evidence** (skill/competence)
|
||||
- **provide ICT consulting advice** (skill/competence)
|
||||
- **query languages** (knowledge)
|
||||
- **resource description framework query language** (knowledge)
|
||||
- **secure sensitive customer's information** (skill/competence)
|
||||
- **security engineering** (knowledge)
|
||||
- **security threats** (knowledge)
|
||||
- **tools for ICT test automation** (knowledge)
|
||||
- **use scripting programming** (skill/competence)
|
||||
- **use software for data preservation** (skill/competence)
|
||||
- **use technology for forensics** (skill/competence)
|
||||
|
||||
## Optional
|
||||
|
||||
- Aircrack (penetration testing tool) (knowledge)
|
||||
- analyse network configuration and performance (skill/competence)
|
||||
- Backbox (penetration testing tool) (knowledge)
|
||||
- BlackArch (knowledge)
|
||||
- Cain and Abel (penetration testing tool) (knowledge)
|
||||
- cloud technologies (knowledge)
|
||||
- collect cyber defence data (skill/competence)
|
||||
- data storage (knowledge)
|
||||
- design computer network (skill/competence)
|
||||
- hardware architectures (knowledge)
|
||||
- hardware platforms (knowledge)
|
||||
- ICT encryption (knowledge)
|
||||
- implement ICT security policies (skill/competence)
|
||||
- information architecture (knowledge)
|
||||
- information security strategy (knowledge)
|
||||
- John The Ripper (penetration testing tool) (knowledge)
|
||||
- Kali Linux (knowledge)
|
||||
- LDAP (knowledge)
|
||||
- legal requirements of ICT products (knowledge)
|
||||
- LINQ (knowledge)
|
||||
- Maltego (knowledge)
|
||||
- manage cloud data and storage (skill/competence)
|
||||
- MDX (knowledge)
|
||||
- Metasploit (knowledge)
|
||||
- N1QL (knowledge)
|
||||
- Nessus (knowledge)
|
||||
- Nexpose (knowledge)
|
||||
- OWASP ZAP (knowledge)
|
||||
- Parrot Security OS (knowledge)
|
||||
- perform data mining (skill/competence)
|
||||
- Samurai Web Testing Framework (knowledge)
|
||||
- SPARQL (knowledge)
|
||||
- THC Hydra (knowledge)
|
||||
- use different communication channels (skill/competence)
|
||||
- WhiteHat Sentinel (knowledge)
|
||||
- Wireshark (knowledge)
|
||||
- XQuery (knowledge)
|
||||
|
||||
<!-- market-evidence -->
|
||||
|
||||
## Market evidence (job-ad analysis, 30 ads, as of 2026-07-11)
|
||||
|
||||
Share of analyzed job ads mentioning the item (threshold ≥ 20 %). Source: JSearch/Adzuna APIs.
|
||||
|
||||
### Hard skills
|
||||
|
||||
- digital forensics — **83 %**
|
||||
- data recovery — **33 %**
|
||||
- incident response — **30 %**
|
||||
- forensic analysis — **23 %**
|
||||
- malware analysis — **20 %**
|
||||
- evidence preservation — **20 %**
|
||||
|
||||
<!-- market-evidence -->
|
||||
49
references/tasks.md
Normal file
49
references/tasks.md
Normal file
@@ -0,0 +1,49 @@
|
||||
# Tasks & work activities — digital forensics expert
|
||||
|
||||
Source: O*NET 30.3, occupation 15-1299.06 (Digital Forensics Analysts).
|
||||
|
||||
## Task statements
|
||||
|
||||
- **[nan]** Adhere to legal policies and procedures related to handling digital media.
|
||||
- **[nan]** Analyze log files or other digital information to identify the perpetrators of network intrusions.
|
||||
- **[nan]** Conduct predictive or reactive analyses on security measures to support cyber security initiatives.
|
||||
- **[nan]** Create system images or capture network settings from information technology environments to preserve as evidence.
|
||||
- **[nan]** Develop plans for investigating alleged computer crimes, violations, or suspicious activity.
|
||||
- **[nan]** Develop policies or requirements for data collection, processing, or reporting.
|
||||
- **[nan]** Duplicate digital evidence to use for data recovery and analysis procedures.
|
||||
- **[nan]** Identify or develop reverse-engineering tools to improve system capabilities or detect vulnerabilities.
|
||||
- **[nan]** Maintain cyber defense software or hardware to support responses to cyber incidents.
|
||||
- **[nan]** Maintain knowledge of laws, regulations, policies or other issuances pertaining to digital forensics or information privacy.
|
||||
- **[nan]** Perform file signature analysis to verify files on storage media or discover potential hidden files.
|
||||
- **[nan]** Perform forensic investigations of operating or file systems.
|
||||
- **[nan]** Perform web service network traffic analysis or waveform analysis to detect anomalies, such as unusual events or trends.
|
||||
- **[nan]** Preserve and maintain digital forensic evidence for analysis.
|
||||
- **[nan]** Recommend cyber defense software or hardware to support responses to cyber incidents.
|
||||
- **[nan]** Recover data or decrypt seized data.
|
||||
- **[nan]** Write and execute scripts to automate tasks, such as parsing large data files.
|
||||
- **[nan]** Write cyber defense recommendations, reports, or white papers using research or experience.
|
||||
- **[nan]** Write reports, sign affidavits, or give depositions for legal proceedings.
|
||||
- **[nan]** Write technical summaries to report findings.
|
||||
|
||||
## Detailed work activities
|
||||
|
||||
- Analyze security of systems, network, or data.
|
||||
- Analyze traffic data.
|
||||
- Compile technical information or documentation.
|
||||
- Develop technical methods or processes.
|
||||
- Enter codes or other information into computers.
|
||||
- Establish operational policies.
|
||||
- Examine records or other types of data to investigate criminal activities.
|
||||
- Identify information technology project resource requirements.
|
||||
- Maintain computer equipment or software.
|
||||
- Maintain knowledge of laws or regulations.
|
||||
- Maintain records, documents, or other files.
|
||||
- Monitor the security of digital information.
|
||||
- Plan production or operational procedures or sequences.
|
||||
- Provide recommendations to others about computer hardware.
|
||||
- Recommend changes to improve computer or information systems.
|
||||
- Record images needed to address work issues.
|
||||
- Testify at legal or legislative proceedings.
|
||||
- Translate information for others.
|
||||
- Write computer programming code.
|
||||
- Write reports or evaluations.
|
||||
85
references/tools.md
Normal file
85
references/tools.md
Normal file
@@ -0,0 +1,85 @@
|
||||
# Tools & technology — digital forensics expert
|
||||
|
||||
Source: O*NET 30.3 'Software Skills' for 15-1299.06.
|
||||
|
||||
| Software | Category | Hot technology |
|
||||
|---|---|---|
|
||||
| Kubernetes | Application server software | yes |
|
||||
| Slack | Cloud-based data access and sharing software | yes |
|
||||
| IBM Terraform | Configuration management software | yes |
|
||||
| Amazon Web Services AWS software | Data base user interface and query software | yes |
|
||||
| Microsoft Access | Data base user interface and query software | yes |
|
||||
| ServiceNow | Data base user interface and query software | yes |
|
||||
| Structured query language SQL | Data base user interface and query software | yes |
|
||||
| C | Development environment software | yes |
|
||||
| Go | Development environment software | yes |
|
||||
| Microsoft Azure software | Development environment software | yes |
|
||||
| Microsoft PowerShell | Development environment software | yes |
|
||||
| Ruby | Development environment software | yes |
|
||||
| Extensible markup language XML | Enterprise application integration software | yes |
|
||||
| Splunk Enterprise | Enterprise system management software | yes |
|
||||
| Ansible software | Expert system software | yes |
|
||||
| Microsoft Active Directory | Internet directory services software | yes |
|
||||
| C# | Object or component oriented development software | yes |
|
||||
| C++ | Object or component oriented development software | yes |
|
||||
| Oracle Java | Object or component oriented development software | yes |
|
||||
| Perl | Object or component oriented development software | yes |
|
||||
| Python | Object or component oriented development software | yes |
|
||||
| R | Object or component oriented development software | yes |
|
||||
| Google Workspace software | Office suite software | yes |
|
||||
| Microsoft Office software | Office suite software | yes |
|
||||
| Apple iOS | Operating system software | yes |
|
||||
| Apple macOS | Operating system software | yes |
|
||||
| Bash | Operating system software | yes |
|
||||
| Linux | Operating system software | yes |
|
||||
| Microsoft Windows | Operating system software | yes |
|
||||
| Microsoft Windows Server | Operating system software | yes |
|
||||
| UNIX | Operating system software | yes |
|
||||
| Microsoft PowerPoint | Presentation software | yes |
|
||||
| Microsoft Excel | Spreadsheet software | yes |
|
||||
| Border Gateway Protocol BGP | Switch or router software | yes |
|
||||
| Hypertext markup language HTML | Web platform development software | yes |
|
||||
| JavaScript | Web platform development software | yes |
|
||||
| PHP | Web platform development software | yes |
|
||||
| Guidance Software EnCase Enterprise | Analytical or scientific software | |
|
||||
| Single sign-on SSO | Authentication server software | |
|
||||
| Platform as a service PaaS | Cloud-based data access and sharing software | |
|
||||
| Enterprise application integration EAI software | Enterprise application integration software | |
|
||||
| Management information systems MIS | Enterprise resource planning ERP software | |
|
||||
| Computer forensic software | Filesystem software | |
|
||||
| Geographic information system GIS systems | Geographic information system | |
|
||||
| Graphical user interface GUI design software | Graphical user interface development software | |
|
||||
| Network directory services software | Internet directory services software | |
|
||||
| AccessData FTK | Network monitoring software | |
|
||||
| Cisco Systems Cisco NetFlow Collection Engine | Network monitoring software | |
|
||||
| IBM QRadar SIEM | Network monitoring software | |
|
||||
| Snort | Network monitoring software | |
|
||||
| Wireshark | Network monitoring software | |
|
||||
| Firewall software | Network security and virtual private network VPN equipment software | |
|
||||
| Intrusion detection system IDS | Network security or virtual private network VPN management software | |
|
||||
| Kali Linux | Program testing software | |
|
||||
| MITRE ATT&CK software | Program testing software | |
|
||||
| System testing software | Program testing software | |
|
||||
| Amazon Simple Storage Service S3 | Storage networking software | |
|
||||
| Metasploit | Transaction security and virus protection software | |
|
||||
| Microsoft Defender Antivirus | Transaction security and virus protection software | |
|
||||
| OpenVAS | Transaction security and virus protection software | |
|
||||
| Portswigger BurP Suite | Transaction security and virus protection software | |
|
||||
| Tenable Nessus | Transaction security and virus protection software | |
|
||||
| Web server software | Transaction server software | |
|
||||
| Security assertion markup language SAML | Web platform development software | |
|
||||
|
||||
<!-- market-evidence -->
|
||||
|
||||
## Market evidence (job-ad analysis, 30 ads, as of 2026-07-11)
|
||||
|
||||
Share of analyzed job ads mentioning the item (threshold ≥ 20 %). Source: JSearch/Adzuna APIs.
|
||||
|
||||
### Tools
|
||||
|
||||
- X-Ways — **33 %**
|
||||
- EnCase — **30 %**
|
||||
- Cellebrite — **23 %**
|
||||
- FTK — **23 %**
|
||||
|
||||
<!-- market-evidence -->
|
||||
Reference in New Issue
Block a user