CybersecurityLegal & ComplianceAI & Agent WorkflowsOpen accessPublished 3 Oct 2026
Guides digital forensics for security incidents—evidence acquisition and chain of custody,
disk/memory/mobile/cloud artifact analysis, log and network forensics, timeline correlation,
malware artifact triage, and investigation reports for legal/IR and expert-witness preparation
outlines (not legal advice). Use when preserving and analyzing forensic artifacts, building
super-timelines, documenting acquisition worksheets, triaging malware samples, or preparing
forensic findings for counsel—not live incident command (incident-responder), SOC alert queue
triage (soc-analyst), authorized penetration testing (penetration-tester), deep binary RE
(reverse-engineer), LLM red team …